Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Endpoint Security

Apple Paid Out $20 Million via Bug Bounty Program

Apple has launched a new security research blog and website, which will also be the new home of the company’s bug bounty program.

Apple has launched a new security research blog and website, which will also be the new home of the company’s bug bounty program.

The tech giant has taken the opportunity to reveal that it has paid out a total of $20 million through its Apple Security Bounty (ASB) program. The average reward in the product category is $40,000, and more than 20 separate payouts for high-impact vulnerabilities exceeded $100,000.

Apple announced a private bug bounty program for iOS in 2016 and a public program covering all of its major software and operating systems in 2019.

In comparison, Microsoft has been paying out more than $13 million every year for the past three years, totaling more than $40 million between July 2019 and July 2022. Google said in July 2021 that it had paid out more than $29 million in the past 10 years and this year it reported awarding a record $8.7 million in 2021 alone.

Facebook has paid out a total of $14 million since 2011. Zoom awarded approximately $1.8 million through its bug bounty program in 2021.

The new Apple Security Research website can be used to report security and privacy issues to Apple, as well as to keep track of their status and communicate with the company.

While there have been many complaints from the security research community regarding Apple’s bug bounty program, the tech giant says it has made improvements. This includes completing initial vulnerability report evaluations faster and making it easier for researchers to report issues and communicate with its teams.

With the new site, Apple is also providing more detailed information on the reward ranges for each product and service. For instance, a device attack via physical access that results in user data extraction can earn up to $250,000. A network attack without user interaction that results in kernel code execution with persistence is worth up to $1 million.

Advertisement. Scroll to continue reading.

Beta software issues have a maximum bounty of $1.5 million, while a Lockdown Mode protection bypass can earn a researcher up to $2 million.

Apple bug bounty program

In the case of vulnerabilities affecting Apple services, the top reward is $100,000, which can be earned for iCloud hacks.

The Apple Security Research website will also provide the research community with technical details on its security technologies. The first technical post published on the website delves into memory safety upgrades in XNU, the kernel at the core of iPhone, iPad, and Mac devices.

Apple also announced that it’s accepting applications for the 2023 Apple Security Research Device program until November 30. As part of this program, researchers are provided a special iPhone that allows them to conduct research without the need to bypass its security features.

*updated information on Facebook bug bounty payout

Related: Apple Patches New macOS, iOS Zero-Days

Related: Apple Pays Out $100,000 for Webcam, User Account Hacking Exploit

Related: Apple Security Flaw: How do ‘Zero-Click’ Attacks Work?

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

Shaun Khalfan has joined payments giant PayPal as SVP, CISO.

UK cybersecurity agency NCSC announced Richard Horne as its new CEO.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

CISO Strategy

SecurityWeek spoke with more than 300 cybersecurity experts to see what is bubbling beneath the surface, and examine how those evolving threats will present...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

CISO Conversations

Joanna Burkey, CISO at HP, and Kevin Cross, CISO at Dell, discuss how the role of a CISO is different for a multinational corporation...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...