Apple doubles top Security Bounty to $2M (up to $5M with bonuses)
Apple doubles top Security Bounty to $2M — Up to $5M with bonuses Apple updated its Security Bounty program in November, significantly raising rewards to encourage research into high-impact vulnerabilities. Key changes include: Top award doubled from $1,000,000 to $2,000,000 for zero-click exploit chains that can achieve remote compromise; total payouts can exceed $5,000,000 when including bonuses (e.g., Lockdown Mode bypasses or beta-software findings). One-click exploit chains: up to $1,000,000 (previously $250,000). Physical-proximity attacks: up to $1,000,000 (previously $250,000). Physical access to locked devices: maximum reward doubled to $500,000. Chaining WebContent code execution with a sandbox escape: up to $300,000. Apple also highlighted new defenses like Lockdown Mode (Safari-focused hardened attack surface) and Memory Integrity Enforcement, designed to reduce memory corruption exploits. In its announcement Apple said the only system-level…
