Big money for bugs: Apple boosts RCE reward to $2 Million

Big money for bugs: Apple boosts RCE reward to $2 Million

New Delhi: Apple recently increased financial rewards for the zero-click remote code execution vulnerabilities by twofold to $2 million as part of an updated bug bounty program, Security Affairs reports said this for Apple. Multi-step exploit chains, including the lockdown mode bypasses or the vulnerabilities discovered in the beta software, also give the larger rewards, with the total payouts potentially exceeding $5 million. The expanded bounty program also covers additional attack types.

Rewards now include up to $300,000 for the one-click WebKit sandbox escapes and up to $1 million for the wireless proximity exploits. Rewards focus on exploits affecting current devices and operating systems, such as the iPhone 17 with Memory Integrity Enforcement. Lower-impact reports remain eligible for $1000 awards. Apple also introduced the Target Flags, enabling researchers to demonstrate exploitability for critical categories like RCE or TCC bypasses and receive faster verification and payouts.

Until the updated awards are published online, they will evaluate all the latest reports against their previous framework as well as the latest one, and they will award the higher amount. And while they were especially motivated to receive complex exploit chains and innovative research, they will continue to review and reward all the reports that significantly impact the security of their users, even if they are not covered by their published categories.

Punit Panchal
Senior Editor

I’m a content writer specializing in tech, creating clear, engaging, and SEO-friendly content that simplifies complex topics. From emerging technologies to product insights, I focus on delivering value-driven content that connects with readers and ranks effectively.

Comments are closed