Get App Open
In App
News on WhatsApp
News on WhatsApp
Open App
LAMF
LAMF

Apple will pay you up to $2 million if you find critical bugs in its software: 5 key things to know

MC Tech Desk | October 11, 2025 / 14:30 IST
1/5
apple
Bigger payouts for top security flaws: Apple is updating its Security Bounty program this November, doubling the top reward from $1 million to $2 million for discovering complex exploit chains that work like advanced spyware attacks and don’t require any user interaction. Some critical vulnerabilities could even earn over $5 million, including bugs in beta software and bypasses of Lockdown Mode in Safari.
2/5
apple
Rewards for user-interaction exploits increased: Researchers who find exploits requiring just one click from the user can now earn up to $1 million, a big jump from the previous $250,000. Similarly, attacks that need physical proximity to a device can earn $1 million, and attacks requiring physical access to locked devices now get up to $500,000.
3/5
apple
Sandbox escape and web exploits recognized: Apple is also offering up to $300,000 for researchers who demonstrate chaining WebContent code execution with a sandbox escape, highlighting the company’s focus on protecting critical system layers.
4/5
apple
Apple’s track record: According to Ivan Krstić, Apple’s VP of security engineering, the company has paid over $35 million to more than 800 security researchers since launching the program. While top payouts are rare, multiple researchers have earned $500,000 or more for discovering significant vulnerabilities.
5/5
apple
Fighting mercenary spyware and advanced attacks: Apple says the only system-level iOS attacks seen in the wild came from mercenary spyware, often linked to state actors targeting specific individuals. Its security features like Lockdown Mode and Memory Integrity Enforcement make these attacks harder to pull off. With the bounty updates, Apple hopes to encourage more advanced research on its toughest attack surfaces, keeping ahead of evolving threats.

Discover the latest Business News, Budget 2025 News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347