iLoungeiLounge
  • News
    • Apple
      • AirPods Pro
      • AirPlay
      • Apps
        • Apple Music
      • iCloud
      • iTunes
      • HealthKit
      • HomeKit
      • HomePod
      • iOS 13
      • Apple Pay
      • Apple TV
      • Siri
    • Rumors
    • Humor
    • Technology
      • CES
    • Daily Deals
    • Articles
    • Web Stories
  • iPhone
    • iPhone Accessories
  • iPad
  • iPod
    • iPod Accessories
  • Apple Watch
    • Apple Watch Accessories
  • Mac
    • MacBook Air
    • MacBook Pro
  • Reviews
    • App Reviews
  • How-to
    • Ask iLounge
Font ResizerAa
iLoungeiLounge
Font ResizerAa
Search
  • News
    • Apple
    • Rumors
    • Humor
    • Technology
    • Daily Deals
    • Articles
    • Web Stories
  • iPhone
    • iPhone Accessories
  • iPad
  • iPod
    • iPod Accessories
  • Apple Watch
    • Apple Watch Accessories
  • Mac
    • MacBook Air
    • MacBook Pro
  • Reviews
    • App Reviews
  • How-to
    • Ask iLounge
Follow US

News › Apple

Apple

Apple’s Bug Bounty program not paying enough to entice hackers

Last updated: May 16, 2021 12:54 pm UTC
By Jesse Hollington
Apple’s Bug Bounty program not paying enough to entice hackers

An Apple program that’s intended to entice hackers to reveal iOS security flaws in exchange for cash is failing to generate the necessary traction due to insufficient cash incentives, Motherboard reports. The program, announced by Apple’s security chief Ivan Krstic at last summer’s Black Hat conference, offers a cash bounty of up to $200,000 to hackers who discover and report vulnerabilities in the company’s products. However, almost a year later, the program appears to have struggled to take off, with many researchers reporting that they can sell exploits for considerably more money on the grey market than the mere $200,000 that Apple is willing to pay.
In fact, there has been no evidence that any hackers have yet claimed any bug bounties from Apple as part of the program, and with iPhone security as tight as it is, the difficulty in finding flaws in the first place makes them extremely valuable on the open market.


Apple’s Bug Bounty program not paying enough to entice hackers

Further, many researchers are also reluctant to report bugs because doing so may in some cases prevent them from continuing their research. Speaking anonymously to Motherboard due to the confidential nature of Apple’s bug bounty program, ten researchers in the program indicated that they have yet to report a bug to Apple, and in fact do not know of anyone who has. They generally all agreed, as one stated, that bugs are “too valuable to report to Apple.”

Apple gathered the group of prominent white-hat hackers to its Cupertino headquarters last September to pitch them on collaborating on the bug bounty program, giving them presentations from Apple security teams, taking them out to dinner, giving them a chance to chat and discuss their work, and meet with Craig Federighi, Apple’s senior vice president of software engineering.


Although the announcement of the program was made publicly, everything else about it has been kept under close wraps with Apple’s usual secrecy, and the program remains invite-only. While Apple offered bounties of up to $200,000, most researchers have pointed out that grey market companies have offered considerably higher payouts, ranging from $1.5 million from Zerodium for a collection of multiple bugs that can jailbreak the iPhone to $500,000 from Exodus Intelligence for similar iOS exploits. These grey market companies specialized in purchasing and compiling exploits which they claim to sell only to corporations to help them protect their own security and to law enforcement and intelligence agencies to help them hack into high-value targets for criminal investigations and counter-terrorrism.


Latest News
The AirPods Pro 3 is $20 Off
The AirPods Pro 3 is $20 Off
1 Min Read
Exynos 2600 Chip 2nm Process Revealed by Samsung
Exynos 2600 Chip 2nm Process Revealed by Samsung
1 Min Read
New Celebrity Ad Campaign Featuring Travis Scott Released by Beats
New Celebrity Ad Campaign Featuring Travis Scott Released by Beats
1 Min Read
Australia Getting Hypertension Notification Feature
Australia Getting Hypertension Notification Feature
1 Min Read
The 14-inch MacBook Pro with M5 Chip 16GB RAM/512GB is $250 Off
The 14-inch MacBook Pro with M5 Chip 16GB RAM/512GB is $250 Off
1 Min Read
Noise and Static on AirPods Pro 3 Still Unfixed
Noise and Static on AirPods Pro 3 Still Unfixed
1 Min Read
New iMac with 24-inch OLED Display May be Brighter With 600 Nits
New iMac with 24-inch OLED Display May be Brighter With 600 Nits
1 Min Read
The 15-inch M4 MacBook Air 256GB Is $250 Off
The 15-inch M4 MacBook Air 256GB Is $250 Off
1 Min Read
Internal Kernel Debug Kit from Apple Reveals Tests for a MacBook with A15 Chip
Internal Kernel Debug Kit from Apple Reveals Tests for a MacBook with A15 Chip
1 Min Read
Apple Currently In Talks With Suppliers for Chip Assembly & Packaging of iPhones in India
Apple Currently In Talks With Suppliers for Chip Assembly & Packaging of iPhones in India
1 Min Read
Apple Allows Easier Battery Replacement For M5 MacBook Pro with 14-inch Display
Apple Allows Easier Battery Replacement For M5 MacBook Pro with 14-inch Display
1 Min Read
The Apple Watch SE 3 44mm GPS is $50 Off
The Apple Watch SE 3 44mm GPS is $50 Off
1 Min Read

iLounge logo

iLounge is an independent resource for all things iPod, iPhone, iPad, and beyond. iPod, iPhone, iPad, iTunes, Apple TV, and the Apple logo are trademarks of Apple Inc.

This website is not affiliated with Apple Inc.
iLounge © 2001 - 2025. All Rights Reserved.
  • Contact Us
  • Submit News
  • About Us
  • Forums
  • Privacy Policy
  • Terms Of Use
Welcome Back!

Sign in to your account

Lost your password?