Apple paid a researcher $100K for reporting a flaw in “Sign in with Apple” in April that could have let attackers hijack any user's account on third-party apps
Context & Ripple Effects
The $100K payout closes a loop that began with Apple's invite-only bug bounty launch in 2016, when a few dozen hand-picked researchers could earn at most $200K per find. In August 2019 Apple widened the program to macOS, watchOS, and Apple TV, raised the ceiling to $1M, and committed to opening it to all researchers — so this April finding, disclosed publicly at the end of May, is an early product of that broadened intake.
The target matters as much as the price: Sign in with Apple is a federated identity layer, so a flaw there doesn't expose one app but any user's account across every third-party service that trusts the sign-in. A single high-severity report can therefore be worth six figures without touching iOS kernel code.
First-order effects
- Apple paid out $100K for the report and patched a vulnerability that, pre-fix, would have let attackers take over users' accounts on third-party apps relying on Sign in with Apple.
Second-order effects
- The publicized payout functions as recruiting for the widened program: within months of disclosure, one research team reported 55 vulnerabilities through the bounty and collected roughly $288K, evidence the expanded scope and payouts are pulling in outside talent.
Third-order effects
- If the pattern holds, bug bounties become standing security procurement rather than PR — Apple's own accounting later put cumulative awards near $20M with twenty-plus individual rewards above $100K, meaning external researchers are now a routine part of how the company finds flaws across its platform.
The trend: Bug bounty programs at major platform vendors are scaling from invite-only experiments into always-on, million-dollar-ceiling channels for outsourced security discovery.