Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Create Fast Growth Companies With Growth Loops

    October 20, 2025

    Ninja Prestige DualBrew System review: espresso and drip coffee don’t get easier than this

    October 19, 2025

    Bluesky adds private bookmarks | TechCrunch

    October 19, 2025
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Apple Bug Bounty Update: Top Payout $2 Million, $35 Million Paid to Date
    Apple Bug Bounty Update: Top Payout  Million,  Million Paid to Date
    Cybersecurity

    Apple Bug Bounty Update: Top Payout $2 Million, $35 Million Paid to Date

    The Tech GuyBy The Tech GuyOctober 12, 2025No Comments4 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Apple on Friday announced significant updates to its bug bounty program and the company is now offering up to $2 million for complex exploit chains. 

    Advertisement

    Since the launch of its public bug bounty program in 2020, Apple has awarded a total of more than $35 million to over 800 security researchers. Multiple hackers earned $500,000 for their work, Apple said.

    The tech giant recently unveiled Memory Integrity Enforcement (MIE), an always-on memory-safety protection for iPhones designed to combat sophisticated attacks such as the ones conducted by mercenary spyware vendors. 

    Apple believes these spyware attacks are the only ones that actually pose a significant threat to its customers and the company now wants to boost the security of its products even further against sophisticated attacks. 

    It’s doing this by harnessing offensive security talent from outside the company, specifically by significantly increasing bug bounties for vulnerabilities such as the ones that would be leveraged in the exploit chains of mercenary spyware attacks.

    Specifically, the top reward for a zero-click exploit chain that achieves remote device compromise, has been increased from $1 million to $2 million. Apple pointed out that this is the base pay and researchers can in theory get as much as $5 million if they earn bonuses for Lockdown Mode bypasses and vulnerabilities discovered in beta software. 

    Apple noted in a call with reporters on Thursday that for someone to earn a $5 million reward is not easy or likely, but it is theoretically possible.

    Apple is also significantly increasing bug bounty payouts for an application sandbox escape (from $150k to $500k), attacks requiring physical access to a locked device (from $250k to $500k), wireless attacks requiring physical proximity (from $250k to $1M), and remote hacking that requires one-click user interaction (from $250k to $1M).

    Advertisement. Scroll to continue reading.

    The company has also announced that one-click attacks through the web browser, which have to bypass its WebKit protections, will be rewarded with up to $300,000 if they can achieve code execution with a sandbox escape. The reward can increase up to $1 million if the exploit chain is taken even further to achieve unsigned code execution with arbitrary entitlements. 

    The tech giant is also boosting rewards for categories where no exploit has been demonstrated to date, such as a Gatekeeper bypass on macOS ($100,000) and unauthorized iCloud access ($1 million). 

    The new payouts will go into effect in November 2025. 

    Apple on Friday also introduced a concept that involves flags, similar to capture-the-flag (CTF) competitions. These so-called ‘Target Flags’ are meant to make it easier for researchers to objectively demonstrate their findings and to know what reward they should expect for their report. 

    “When researchers demonstrate security issues using Target Flags, the specific flag that’s captured objectively demonstrates a given level of capability — for example, register control, arbitrary read/write, or code execution — and directly correlates to the reward amount, making the award determination more transparent than ever,” Apple explained. 

    “Because Target Flags can be programmatically verified by Apple as part of submitted findings, researchers who submit eligible reports with Target Flags will receive notification of their bounty award immediately upon our validation of the captured flag,” it added.

    Target Flags are supported on iOS, iPadOS, macOS, visionOS, watchOS, and tvOS.

    Apple also announced that exceptional research will continue to receive bonuses, and it has decided that even low-impact vulnerabilities may be rewarded with $1,000 to encourage researchers to continue reporting their findings.

    Related: Apple Seeks Researchers for 2026 iPhone Security Program

    Related: Apple Updates iOS and macOS to Prevent Malicious Font Attacks

    Related: Apple Sends Fresh Wave of Spyware Notifications to French Users

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Sophisticated Malware Deployed in Oracle EBS Zero-Day Attacks

    October 12, 2025

    ZDI Drops 13 Unpatched Ivanti Endpoint Manager Vulnerabilities

    October 11, 2025

    Juniper Networks Patches Critical Junos Space Vulnerabilities

    October 11, 2025

    RondoDox Botnet Takes ‘Exploit Shotgun’ Approach

    October 11, 2025

    In Other News: Gladinet Flaw Exploitation, Attacks on ICS Honeypot, ClayRat Spyware

    October 10, 2025

    Cisco, Fortinet, Palo Alto Networks Devices Targeted in Coordinated Campaign

    October 10, 2025
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views

    Facebook updates its algorithm to give users more control over which videos they see

    October 8, 20257 Views

    Huawei Watch GT 6 Pro review

    October 12, 20256 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Create Fast Growth Companies With Growth Loops

    October 20, 2025

    Ninja Prestige DualBrew System review: espresso and drip coffee don’t get easier than this

    October 19, 2025

    Bluesky adds private bookmarks | TechCrunch

    October 19, 2025
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2025 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.