Moneycontrol PRO
LAMF
LAMF

Apple offers to pay up to $2 million for finding Pegasus-like spyware in iPhones and other devices

Apple’s revamped program will offer $2 million for exploit chains capable of achieving “mercenary spyware-level” attacks — the highest confirmed payout in the cybersecurity industry.
October 10, 2025 / 19:20 IST
Apple iPhone

Apple has announced a sweeping expansion of its Security Bounty program, calling it the “next major chapter” in its effort to strengthen user privacy and platform security. The company has already paid over $35 million to 800 researchers and is now doubling its top payout to an industry-leading $2 million, with rewards in some categories exceeding $5 million.

Record-breaking payouts for top exploits

Apple’s revamped program will offer $2 million for exploit chains capable of achieving “mercenary spyware-level” attacks — the highest confirmed payout in the cybersecurity industry. The company says its bonus system can more than double this figure, taking total rewards beyond $5 million for those who identify vulnerabilities that bypass Lockdown Mode or are found in beta software.

In addition, Apple is significantly raising rewards in other high-priority areas: a complete Gatekeeper bypass now carries a $100,000 bounty, while broad unauthorised access to iCloud could earn up to $1 million — though Apple notes no successful exploit has been demonstrated so far in either category.

Expanding to new attack surfaces

The expanded program will now cover a wider range of threats. Apple is adding new categories such as one-click WebKit sandbox escapes, which can earn up to $300,000, and wireless proximity exploits that target any radio interface, with rewards of up to $1 million. These updates reflect Apple’s focus on strengthening defences against advanced remote and zero-click attacks.

Faster, more transparent rewards

A major new addition is Target Flags, a system that allows researchers to objectively prove the exploitability of vulnerabilities, including remote code execution and Transparency, Consent, and Control (TCC) bypasses. Reports submitted with Target Flags will qualify for accelerated awards — meaning verified findings can be paid out even before Apple releases a patch.

Security for at-risk users

Beyond financial incentives, Apple is launching a new initiative to support civil society groups and individuals vulnerable to spyware. The company will provide 1,000 iPhone 17 devices — featuring Memory Integrity Enforcement, its strongest memory safety protection yet — to organisations helping at-risk users.

Launch timeline

The updated Apple Security Bounty program takes effect in November 2025, when Apple will publish a complete list of new reward tiers, expanded categories, and bonus structures on its Security Research website.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

MC Tech Desk Read the latest and trending tech news—stay updated on AI, gadgets, cybersecurity, software updates, smartphones, blockchain, space tech, and the future of innovation.
first published: Oct 10, 2025 07:19 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347