Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    The future of TVs is bright, but I don’t think it’s MicroLED

    April 28, 2026

    Plex has a brutally realistic crime drama you can binge for free, and it’s not in English

    April 27, 2026

    NYT Strands hints and answers for Tuesday, April 28 (game #786)

    April 27, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Apple Bug Bounty Update: Top Payout $2 Million, $35 Million Paid to Date
    Apple Bug Bounty Update: Top Payout  Million,  Million Paid to Date
    Cybersecurity

    Apple Bug Bounty Update: Top Payout $2 Million, $35 Million Paid to Date

    The Tech GuyBy The Tech GuyOctober 12, 2025No Comments4 Mins Read1 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Apple on Friday announced significant updates to its bug bounty program and the company is now offering up to $2 million for complex exploit chains. 

    Advertisement

    Since the launch of its public bug bounty program in 2020, Apple has awarded a total of more than $35 million to over 800 security researchers. Multiple hackers earned $500,000 for their work, Apple said.

    The tech giant recently unveiled Memory Integrity Enforcement (MIE), an always-on memory-safety protection for iPhones designed to combat sophisticated attacks such as the ones conducted by mercenary spyware vendors. 

    Apple believes these spyware attacks are the only ones that actually pose a significant threat to its customers and the company now wants to boost the security of its products even further against sophisticated attacks. 

    It’s doing this by harnessing offensive security talent from outside the company, specifically by significantly increasing bug bounties for vulnerabilities such as the ones that would be leveraged in the exploit chains of mercenary spyware attacks.

    Specifically, the top reward for a zero-click exploit chain that achieves remote device compromise, has been increased from $1 million to $2 million. Apple pointed out that this is the base pay and researchers can in theory get as much as $5 million if they earn bonuses for Lockdown Mode bypasses and vulnerabilities discovered in beta software. 

    Apple noted in a call with reporters on Thursday that for someone to earn a $5 million reward is not easy or likely, but it is theoretically possible.

    Apple is also significantly increasing bug bounty payouts for an application sandbox escape (from $150k to $500k), attacks requiring physical access to a locked device (from $250k to $500k), wireless attacks requiring physical proximity (from $250k to $1M), and remote hacking that requires one-click user interaction (from $250k to $1M).

    Advertisement. Scroll to continue reading.

    The company has also announced that one-click attacks through the web browser, which have to bypass its WebKit protections, will be rewarded with up to $300,000 if they can achieve code execution with a sandbox escape. The reward can increase up to $1 million if the exploit chain is taken even further to achieve unsigned code execution with arbitrary entitlements. 

    The tech giant is also boosting rewards for categories where no exploit has been demonstrated to date, such as a Gatekeeper bypass on macOS ($100,000) and unauthorized iCloud access ($1 million). 

    The new payouts will go into effect in November 2025. 

    Apple on Friday also introduced a concept that involves flags, similar to capture-the-flag (CTF) competitions. These so-called ‘Target Flags’ are meant to make it easier for researchers to objectively demonstrate their findings and to know what reward they should expect for their report. 

    “When researchers demonstrate security issues using Target Flags, the specific flag that’s captured objectively demonstrates a given level of capability — for example, register control, arbitrary read/write, or code execution — and directly correlates to the reward amount, making the award determination more transparent than ever,” Apple explained. 

    “Because Target Flags can be programmatically verified by Apple as part of submitted findings, researchers who submit eligible reports with Target Flags will receive notification of their bounty award immediately upon our validation of the captured flag,” it added.

    Target Flags are supported on iOS, iPadOS, macOS, visionOS, watchOS, and tvOS.

    Apple also announced that exceptional research will continue to receive bonuses, and it has decided that even low-impact vulnerabilities may be rewarded with $1,000 to encourage researchers to continue reporting their findings.

    Related: Apple Seeks Researchers for 2026 iPhone Security Program

    Related: Apple Updates iOS and macOS to Prevent Malicious Font Attacks

    Related: Apple Sends Fresh Wave of Spyware Notifications to French Users

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    OpenSSH Flaw Allowing Full Root Shell Access Lurked for 15 Years

    April 27, 2026

    Incomplete Windows Patch Opens Door to Zero-Click Attacks

    April 27, 2026

    Bitwarden NPM Package Hit in Supply Chain Attack

    April 26, 2026

    Vulnerabilities Patched in CrowdStrike, Tenable Products

    April 26, 2026

    Trump Administration Vows Crackdown on Chinese Companies ‘Exploiting’ AI Models Made in US

    April 26, 2026

    US Federal Agency’s Cisco Firewall Infected With ‘Firestarter’ Backdoor

    April 25, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views

    ChatGPT Group Chats are here … but not for everyone (yet)

    November 14, 20258 Views

    Facebook updates its algorithm to give users more control over which videos they see

    October 8, 20258 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    The future of TVs is bright, but I don’t think it’s MicroLED

    April 28, 2026

    Plex has a brutally realistic crime drama you can binge for free, and it’s not in English

    April 27, 2026

    NYT Strands hints and answers for Tuesday, April 28 (game #786)

    April 27, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.