/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Apple paid a researcher $100K for reporting a flaw in “Sign in with Apple” in April that could have let attackers hijack any user's account on third-party apps

The Hacker News :

The Hacker News

Context & Ripple Effects

The $100K payout closes a loop that began with Apple's invite-only bug bounty launch in 2016, when a few dozen hand-picked researchers could earn at most $200K per find. In August 2019 Apple widened the program to macOS, watchOS, and Apple TV, raised the ceiling to $1M, and committed to opening it to all researchers — so this April finding, disclosed publicly at the end of May, is an early product of that broadened intake.

The target matters as much as the price: Sign in with Apple is a federated identity layer, so a flaw there doesn't expose one app but any user's account across every third-party service that trusts the sign-in. A single high-severity report can therefore be worth six figures without touching iOS kernel code.

First-order effects

  • Apple paid out $100K for the report and patched a vulnerability that, pre-fix, would have let attackers take over users' accounts on third-party apps relying on Sign in with Apple.

Second-order effects

  • The publicized payout functions as recruiting for the widened program: within months of disclosure, one research team reported 55 vulnerabilities through the bounty and collected roughly $288K, evidence the expanded scope and payouts are pulling in outside talent.

Third-order effects

  • If the pattern holds, bug bounties become standing security procurement rather than PR — Apple's own accounting later put cumulative awards near $20M with twenty-plus individual rewards above $100K, meaning external researchers are now a routine part of how the company finds flaws across its platform.

The trend: Bug bounty programs at major platform vendors are scaling from invite-only experiments into always-on, million-dollar-ceiling channels for outsourced security discovery.

Discussion

  • @bhavukjain1 Bhavuk Jain on x
    Zero-day in Sign in with Apple - bounty $100k https://bhavukjain.com/...
  • @scott3142 Scott Morgan on x
    Very interesting discussion of a zero-day security vulnerability recently found in “Sign-in with Apple” - not a bad way to earn $100k! #cybersecurity https://bhavukjain.com/... https://twitter.com/...
  • @artemr Artem Russakovskii on x
    This bug in @Apple ID could have been catastrophic if it wasn't responsibly reported. Wow. “This bug could have resulted in a full account takeover of user accounts on that third party application irrespective of a victim having a valid Apple ID or not.” https://bhavukjain1.githu…
  • @thehackersnews @thehackersnews on x
    ⚡ A highly critical #vulnerability affecting Apple's ‘Sign in with Apple’ feature could have let attackers hack into anyone's account on 3rd-party service or apps. Read details here ➤ https://thehackernews.com/... Apple paid @bhavukjain1 a whopping $100,000 bug bounty for this fl…
  • @martenmickos Mrten Mickos on x
    There is good in the world. 27-year old Bhavuk Jain of Delhi found a critical authentication bug in Apple who promptly fixed it and paid a $100,000 bounty for the find. https://bhavukjain.com/... - The internet can be the global equalizer of opportunity and spreader of goodness