Apple increases bug bounty payouts for zero-click RCE vulnerabilities
Summary
Hide ▲
Show ▼
Apple has expanded and redesigned its bug bounty program, doubling maximum payouts and adding new research categories. The highest reward is now $2 million for zero-click remote code execution (RCE) vulnerabilities, with a bonus system that can exceed $5 million. The program now includes higher payouts for various types of vulnerabilities, including one-click remote attacks, wireless proximity attacks, and unauthorized iCloud access. Apple also plans to distribute secured iPhone 17 devices to civil society organizations and researchers in 2026. The changes aim to incentivize the discovery and reporting of sophisticated security issues, particularly those exploited by mercenary spyware. The program has awarded $35 million to 800 security researchers since its inception in 2020. The expansion includes a $100,000 reward for a complete Gatekeeper bypass and a $1 million reward for broad unauthorized iCloud access. Apple's latest bug bounty announcement is a response to the growth of commercial spyware activity, with the UK’s National Cyber Security Centre (NCSC) estimating that the commercial cyber intrusion sector doubles every 10 years.
Timeline
-
10.10.2025 19:50 2 articles · 4d ago
Apple increases bug bounty payouts for zero-click RCE vulnerabilities
Apple has announced a major expansion and redesign of its bug bounty program, doubling maximum payouts and adding new research categories. The highest reward is now $2 million for zero-click remote code execution (RCE) vulnerabilities. The program now includes higher payouts for various types of vulnerabilities, including one-click remote attacks, wireless proximity attacks, and unauthorized iCloud access. Apple also plans to distribute secured iPhone 17 devices to civil society organizations and researchers in 2026. Apple has paid $35 million to more than 800 security researchers since the launch of the Apple Security Bounty program in 2020. The program includes a bonus system that can more than double the reward, with a maximum payout in excess of $5 million. The bug bounty program now includes a $100,000 reward for a complete Gatekeeper bypass and a $1 million reward for broad unauthorized iCloud access. Apple's latest bug bounty announcement is a response to the growth of commercial spyware activity.
Show sources
- Apple now offers $2 million for zero-click RCE vulnerabilities — www.bleepingcomputer.com — 10.10.2025 19:50
- Apple Bug Bounty Payouts Can Now Top $5m — www.infosecurity-magazine.com — 13.10.2025 12:30
Information Snippets
-
Apple's bug bounty program was launched in 2020.
First reported: 10.10.2025 19:501 source, 1 articleShow sources
- Apple now offers $2 million for zero-click RCE vulnerabilities — www.bleepingcomputer.com — 10.10.2025 19:50
-
The highest reward has been doubled to $2 million for zero-click remote compromise vulnerabilities.
First reported: 10.10.2025 19:502 sources, 2 articlesShow sources
- Apple now offers $2 million for zero-click RCE vulnerabilities — www.bleepingcomputer.com — 10.10.2025 19:50
- Apple Bug Bounty Payouts Can Now Top $5m — www.infosecurity-magazine.com — 13.10.2025 12:30
-
Payouts can go as high as $5 million through the bonus system.
First reported: 10.10.2025 19:502 sources, 2 articlesShow sources
- Apple now offers $2 million for zero-click RCE vulnerabilities — www.bleepingcomputer.com — 10.10.2025 19:50
- Apple Bug Bounty Payouts Can Now Top $5m — www.infosecurity-magazine.com — 13.10.2025 12:30
-
New payout categories include one-click remote attacks, wireless proximity attacks, and unauthorized iCloud access.
First reported: 10.10.2025 19:502 sources, 2 articlesShow sources
- Apple now offers $2 million for zero-click RCE vulnerabilities — www.bleepingcomputer.com — 10.10.2025 19:50
- Apple Bug Bounty Payouts Can Now Top $5m — www.infosecurity-magazine.com — 13.10.2025 12:30
-
Apple will distribute secured iPhone 17 devices to civil society organizations and researchers in 2026.
First reported: 10.10.2025 19:501 source, 1 articleShow sources
- Apple now offers $2 million for zero-click RCE vulnerabilities — www.bleepingcomputer.com — 10.10.2025 19:50
-
The program has awarded $35 million to 800 security researchers since its inception.
First reported: 10.10.2025 19:502 sources, 2 articlesShow sources
- Apple now offers $2 million for zero-click RCE vulnerabilities — www.bleepingcomputer.com — 10.10.2025 19:50
- Apple Bug Bounty Payouts Can Now Top $5m — www.infosecurity-magazine.com — 13.10.2025 12:30
-
Apple's bug bounty program includes a bonus system that can more than double the reward, with a maximum payout in excess of $5 million.
First reported: 13.10.2025 12:301 source, 1 articleShow sources
- Apple Bug Bounty Payouts Can Now Top $5m — www.infosecurity-magazine.com — 13.10.2025 12:30
-
The bug bounty program now includes a $100,000 reward for a complete Gatekeeper bypass.
First reported: 13.10.2025 12:301 source, 1 articleShow sources
- Apple Bug Bounty Payouts Can Now Top $5m — www.infosecurity-magazine.com — 13.10.2025 12:30
-
The bug bounty program now includes a $1 million reward for broad unauthorized iCloud access.
First reported: 13.10.2025 12:301 source, 1 articleShow sources
- Apple Bug Bounty Payouts Can Now Top $5m — www.infosecurity-magazine.com — 13.10.2025 12:30
-
Apple has paid $35 million to more than 800 security researchers since the launch of the Apple Security Bounty program in 2020.
First reported: 13.10.2025 12:301 source, 1 articleShow sources
- Apple Bug Bounty Payouts Can Now Top $5m — www.infosecurity-magazine.com — 13.10.2025 12:30
-
Apple's latest bug bounty announcement is a response to the growth of commercial spyware activity.
First reported: 13.10.2025 12:301 source, 1 articleShow sources
- Apple Bug Bounty Payouts Can Now Top $5m — www.infosecurity-magazine.com — 13.10.2025 12:30
-
The UK’s National Cyber Security Centre (NCSC) estimates that the commercial cyber intrusion sector doubles every 10 years.
First reported: 13.10.2025 12:301 source, 1 articleShow sources
- Apple Bug Bounty Payouts Can Now Top $5m — www.infosecurity-magazine.com — 13.10.2025 12:30
-
Apple is introducing a new way for researchers to objectively demonstrate exploitability in several popular bounty categories under the 'Target Flags' initiative.
First reported: 13.10.2025 12:301 source, 1 articleShow sources
- Apple Bug Bounty Payouts Can Now Top $5m — www.infosecurity-magazine.com — 13.10.2025 12:30
-
Apple has expanded other bounty categories, including one-click WebKit sandbox escapes and wireless proximity exploits over any radio.
First reported: 13.10.2025 12:301 source, 1 articleShow sources
- Apple Bug Bounty Payouts Can Now Top $5m — www.infosecurity-magazine.com — 13.10.2025 12:30
Similar Happenings
Zeroday.Cloud Hacking Competition Announced with $4.5 Million in Prizes
The Zeroday.Cloud hacking competition, announced by Wiz, offers $4.5 million in bug bounties for exploits in widely used cloud software. The event, scheduled for December 10-11 at the Black Hat Europe conference in London, covers six categories: AI, Kubernetes, containers, web servers, databases, and DevOps tools. Participants must submit entries by December 1 and demonstrate exploits live at the event. The competition has faced controversy due to alleged rule copying from Trend Micro's Pwn2Own hacking competition. Wiz has partnered with AWS, Google Cloud, and Microsoft for the event. Google is also in the process of acquiring Wiz for $32 billion. Specific bounties range from $10,000 to $300,000, with detailed conditions and resources provided for each target.