A group of researchers describe how, as part of Apple bug bounty program, they've uncovered 55 vulnerabilities in the past 3 months and received ~$288K so far
Between the period of July 6th to October 6th myself, Brett Buerhaus, Ben Sadeghipour, Samuel Erb, and Tanner Barnes worked together …
Context & Ripple Effects
Apple's bounty program has been scaling steadily since its invite-only launch with a few dozen researchers in 2016, then widened to macOS, watchOS, and Apple TV with a $1M maximum payout and a plan to open it to all researchers in the fall of 2019. This report is the first detailed look at what that open door produced at scale: a five-person team working July through October 2020.
The scale matters because it shows the program functioning as designed after expansion — earlier single-flaw reports like the $100K 'Sign in with Apple' account-hijack payout demonstrated individual rewards, while this disclosure shows sustained team-based hunting yielding 55 findings and roughly $288K in one quarter.
First-order effects
- Sam Curry, Brett Buerhaus, Ben Sadeghipour, Samuel Erb, and Tanner Barnes collectively banked ~$288K across 55 vulnerabilities in three months, validating team-based bug hunting against Apple's expanded scope.
- Apple now has 55 confirmed flaws to patch across its platforms, each disclosed through the sanctioned channel rather than sold or exploited privately.
Second-order effects
- Other independent researchers can benchmark their own effort against these payouts, pushing more hunters toward Apple's program instead of gray-market exploit sales — exactly the behavior the 2019 expansion to all researchers was built to invite.
- Rival platform vendors face pressure to match both the payout ceiling and the breadth of coverage, since a program capped below Apple's $1M maximum looks thin by comparison.
Third-order effects
- If the pattern holds, bug bounties harden from side channel into core security infrastructure: Apple's own later accounting of ~$20M total awarded, including twenty $100K+ rewards, confirms the spend is recurring and structural rather than episodic.
- Team-based research groups operating like small businesses — five specialists splitting quarterly revenue — point toward professionalization of vulnerability research around large platform vendors' programs.
The trend: Platform vendors are turning bug bounty programs into standing, open-enrollment security pipelines where professional researcher teams, not lone finders, supply the bulk of high-impact disclosures.