Apple says it has awarded researchers ~$20M total, including 20 rewards of $100K+ each for high-impact issues, since opening its bug bounty in December 2019
Along with announcing its new Lockdown Mode feature this past summer, the company mentioned an upgraded bounty program, a donation to fund ethical security research, and more.
9to5MacMichael Potuck
Context & Ripple Effects
Apple's bounty program has scaled in three steps: an invite-only pilot with a few dozen researchers in 2016, an expansion to macOS, watchOS, and Apple TV with a $1M maximum payout in 2019, and full public opening that December. The ~$20M disclosed total is the first aggregate accounting of what that build-out has actually paid out.
The disclosure lands alongside this summer's Lockdown Mode launch and a donation to fund ethical security research, framing the bounty less as ad-hoc rewards and more as one pillar of a broader defensive push aimed at users targeted by high-end attacks.
First-order effects
Security researchers now have published proof that Apple's top-tier payouts are real — 20 individual awards of $100K+ since December 2019 — which directly affects where independent researchers spend their hunting time.
Apple gets a public counter-narrative to spyware-driven criticism of iOS security at the same moment it is marketing Lockdown Mode to at-risk users.
Second-order effects
The donation to fund ethical security research extends Apple's spend beyond its own bug queue, subsidizing the research ecosystem that feeds the program and raising the baseline other vendors must match to attract the same talent.
Rival platform vendors face pressure to publish their own aggregate payout figures; Apple has effectively set the disclosure benchmark against which competitors' bounty programs will be measured.
Third-order effects
If the pattern holds, vulnerability bounties harden from PR gesture into standing security procurement — a recurring line item tied to product launches like Lockdown Mode — shifting part of the industry's defense economics from internal testing budgets to external researcher markets.
The trend: Platform vendors are institutionalizing bug bounties as core security infrastructure, with payout scale and transparency becoming competitive differentiators.
Finally, Apple is paying for vulnerabilities that are demanded most by governments and NSO-like companies! A $2 million bonus for Lockdown mode was introduced a while ago. It's a feature designed to reduce the attack vectors of iOS. https://security.apple.com/... https://twitter.…
Apple listens to researchers and finally shared some payout examples on their new security website - https://security.apple.com/... https://twitter.com/...
A few years ago, I was mostly agnostic on some of the security assertions made by Apple, but since iOS 14 their work has genuinely put exploitation mostly out of reach to all but very few. It is genuinely impressive work, even if it goes mostly under the radar. Sincere congrats.
Apple just launched a new security blog. 🤯🤯🤯 After seeing https://googleprojectzero.blogspot.com/ , this is a step in the right direction for Apple. 🔐 Read about all the new changes to the Apple Security Bounty program. 👇 https://security.apple.com/... https://twitter.com/... ht…
Interesting that Apple's specialized iPhones for security research are “not available in any U.S. embargoed countries or region ... or on any other restricted party lists.” https://security.apple.com/...
@bruienne Wait, Apple's going to talk? Publicly?! About security issues?!? 🤯 Uhm, Dr. Strange, have you been fiddling around with the multiverse again? I'm not sure I'm in the right universe... 😄
Apple said the program has an average payout of $40,000 and also dished out 20 separate rewards of over $100,000 for high-impact issues. “To our knowledge, this makes Apple Security Bounty the fastest-growing bounty program in industry history.”
Sincere congratulations to everyone at Apple who's worked on all of this security engineering the past few years. Some of the most genuinely impressive leaps in anti-exploit engineering in the industry has been at Apple over the past couple years. https://twitter.com/...