iLoungeiLounge
  • News
    • Apple
      • AirPods Pro
      • AirPlay
      • Apps
        • Apple Music
      • iCloud
      • iTunes
      • HealthKit
      • HomeKit
      • HomePod
      • iOS 13
      • Apple Pay
      • Apple TV
      • Siri
    • Rumors
    • Humor
    • Technology
      • CES
    • Daily Deals
    • Articles
    • Web Stories
  • iPhone
    • iPhone Accessories
  • iPad
  • iPod
    • iPod Accessories
  • Apple Watch
    • Apple Watch Accessories
  • Mac
    • MacBook Air
    • MacBook Pro
  • Reviews
    • App Reviews
  • How-to
    • Ask iLounge
Font ResizerAa
iLoungeiLounge
Font ResizerAa
Search
  • News
    • Apple
    • Rumors
    • Humor
    • Technology
    • Daily Deals
    • Articles
    • Web Stories
  • iPhone
    • iPhone Accessories
  • iPad
  • iPod
    • iPod Accessories
  • Apple Watch
    • Apple Watch Accessories
  • Mac
    • MacBook Air
    • MacBook Pro
  • Reviews
    • App Reviews
  • How-to
    • Ask iLounge
Follow US

News › Apple

Apple

Apple’s Bug Bounty program not paying enough to entice hackers

Last updated: May 16, 2021 12:54 pm UTC
By Jesse Hollington
Apple’s Bug Bounty program not paying enough to entice hackers

An Apple program that’s intended to entice hackers to reveal iOS security flaws in exchange for cash is failing to generate the necessary traction due to insufficient cash incentives, Motherboard reports. The program, announced by Apple’s security chief Ivan Krstic at last summer’s Black Hat conference, offers a cash bounty of up to $200,000 to hackers who discover and report vulnerabilities in the company’s products. However, almost a year later, the program appears to have struggled to take off, with many researchers reporting that they can sell exploits for considerably more money on the grey market than the mere $200,000 that Apple is willing to pay.
In fact, there has been no evidence that any hackers have yet claimed any bug bounties from Apple as part of the program, and with iPhone security as tight as it is, the difficulty in finding flaws in the first place makes them extremely valuable on the open market.


Apple’s Bug Bounty program not paying enough to entice hackers

Further, many researchers are also reluctant to report bugs because doing so may in some cases prevent them from continuing their research. Speaking anonymously to Motherboard due to the confidential nature of Apple’s bug bounty program, ten researchers in the program indicated that they have yet to report a bug to Apple, and in fact do not know of anyone who has. They generally all agreed, as one stated, that bugs are “too valuable to report to Apple.”

Apple gathered the group of prominent white-hat hackers to its Cupertino headquarters last September to pitch them on collaborating on the bug bounty program, giving them presentations from Apple security teams, taking them out to dinner, giving them a chance to chat and discuss their work, and meet with Craig Federighi, Apple’s senior vice president of software engineering.


Although the announcement of the program was made publicly, everything else about it has been kept under close wraps with Apple’s usual secrecy, and the program remains invite-only. While Apple offered bounties of up to $200,000, most researchers have pointed out that grey market companies have offered considerably higher payouts, ranging from $1.5 million from Zerodium for a collection of multiple bugs that can jailbreak the iPhone to $500,000 from Exodus Intelligence for similar iOS exploits. These grey market companies specialized in purchasing and compiling exploits which they claim to sell only to corporations to help them protect their own security and to law enforcement and intelligence agencies to help them hack into high-value targets for criminal investigations and counter-terrorrism.


Latest News
The Apple Watch SE 3 44mm GPS Is $30 Off
The Apple Watch SE 3 44mm GPS Is $30 Off
1 Min Read
Device Designed By Jony Ive Delayed Until Next Year
Device Designed By Jony Ive Delayed Until Next Year
1 Min Read
New Games Coming To Apple Arcade With Big Updates For Current Titles
New Games Coming To Apple Arcade With Big Updates For Current Titles
1 Min Read
Apple Rolls Out New Challenge For Apple Watch
Apple Rolls Out New Challenge For Apple Watch
1 Min Read
The 13-inch M3 iPad Air Is $119 Off
The 13-inch M3 iPad Air Is $119 Off
1 Min Read
AirPods Pro 4 May Come with Cameras
AirPods Pro 4 May Come with Cameras
1 Min Read
Go and Free ChatGPT Tiers Now Have Ads
Go and Free ChatGPT Tiers Now Have Ads
1 Min Read
Budget-Friendly Bundles Introduced By YouTube TV
Budget-Friendly Bundles Introduced By YouTube TV
1 Min Read
The 4-pack 1st Generation AirTag Is $35 Off
The 4-pack 1st Generation AirTag Is $35 Off
1 Min Read
Apple May Be Planning Something Big To Celebrate 50th Anniversary
Apple May Be Planning Something Big To Celebrate 50th Anniversary
1 Min Read
MacBook Pros with M5 and M5 Pro Chips May Launch in March
MacBook Pros with M5 and M5 Pro Chips May Launch in March
1 Min Read
The Apple Watch Series 11 42mm Cell Is $100 Off
The Apple Watch Series 11 42mm Cell Is $100 Off
1 Min Read

iLounge logo

iLounge is an independent resource for all things iPod, iPhone, iPad, and beyond. iPod, iPhone, iPad, iTunes, Apple TV, and the Apple logo are trademarks of Apple Inc.

This website is not affiliated with Apple Inc.
iLounge © 2001 - 2025. All Rights Reserved.
  • Contact Us
  • Submit News
  • About Us
  • Forums
  • Privacy Policy
  • Terms Of Use
Welcome Back!

Sign in to your account

Lost your password?