Apple has announced a significant expansion of its bug bounty program, raising the maximum payout for the most dangerous exploit chains to $2 million, with the potential for total rewards to reach $5 million when including bonuses. The company made this announcement at the Hexacon offensive security conference in Paris, emphasizing its commitment to incentivizing security researchers to report critical vulnerabilities rather than selling them to malicious actors. The new $2 million maximum applies specifically to exploit chains that could be abused for spyware, reflecting the growing threat posed by the mercenary spyware industry. Apple’s bonus structure further increases rewards for vulnerabilities that bypass Lockdown Mode, a security feature designed to protect users from sophisticated attacks, as well as for exploits discovered in beta versions of Apple software. The company’s bug bounty program now offers increased rewards across five key attack vectors, including full Gatekeeper bypasses with no user interaction, exploit chains involving WebKit code execution and sandbox escapes, unauthorized iCloud access, and wireless proximity exploits over all radio interfaces. For example, a full Gatekeeper bypass can earn $100,000, while a complex exploit chain involving WebKit, sandbox escape, and arbitrary entitlements can reach $1 million. Apple’s updated program ensures that the highest rewards are reserved for vulnerabilities affecting the latest versions of its software and hardware, which have the most advanced security protections. The company has also introduced Target Flags, a new mechanism to help researchers focus on specific areas of interest. Apple’s leadership has stated that these changes are intended to match the increasing difficulty and value of finding critical vulnerabilities in its ecosystem, especially as attackers continue to evolve their techniques. The company acknowledges that the time and expertise required to discover such vulnerabilities are considerable, and the new rewards are designed to reflect that effort. Apple’s move is seen as a direct response to the escalating arms race with mercenary spyware vendors, who are willing to pay high prices for zero-click exploits. The expanded bug bounty program is expected to attract more top-tier security researchers to responsibly disclose vulnerabilities. Apple’s approach also includes rewarding individual components of exploit chains, not just the full chain, to encourage incremental security improvements. The company’s ongoing investment in security features like Lockdown Mode and Memory Integrity Enforcement demonstrates its proactive stance against advanced threats. By offering some of the highest bug bounty rewards in the industry, Apple aims to set a new standard for vulnerability disclosure incentives. The changes to the bug bounty program will take effect next month, and Apple has indicated its willingness to pay out millions of dollars to researchers who help protect its users from the most severe threats.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
Coverage of the updated program said Apple also introduced bonus payouts that can raise rewards to as much as $5 million for zero-click spyware-class exploits that bypass Lockdown Mode. This expanded the scope of the announcement beyond the new $2 million base maximum.
Apple announced changes to its Security Bounty program, increasing the maximum reward to $2 million for qualifying zero-click remote code execution exploit chains. Multiple reports describe the move as a response to the growing threat from high-end exploit development and commercial spyware activity.
See what this changes for your reporting obligations and which controls it puts on the clock.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.