Tuesday, November 12, 2024
HomeAppleApple to Pay Up to $1 Million For Hackers Who Can Gain...

Apple to Pay Up to $1 Million For Hackers Who Can Gain Complete Control Over iPhone

Published on

Malware protection

Apple expands its bug bounty program to cover all operating systems that include macOS, watchOS, tvOS, iPadOS, and iCloud along with the iOS bug bounty program.

The tech giant has confirmed the expansion at Black Hat conference held in Las Vegas. Previously Apple has limited the bug bounty program only to iOS and limited researchers only can participate.

Apple Security Bounty

Now the Apple bug bounty program is open for all researchers and the company has increased payouts from $200,000 to $1 million.

The researchers who discover critical vulnerabilities such as zero-click full chain kernel code execution attack will get $1 million payouts and for other vulnerabilities, the rewards will be lesser. Here are the complete payout details.

- Advertisement - SIEM as a Service
Apple Security Payout Details

Apple Special Phone

Ivan Krstić, Head of Apple Security Engineering and Architecture made the announcement, he also added that the Apple special phone will be available for qualified researchers starting from next year.

These special phones are a step below the rooted devices, that lets researchers to inspect memory for vulnerabilities and to see what happens at the code level. This program was reported by Forbes earlier.

Also, the researchers who found vulnerabilities in pre-release builds are eligible to get an additional 50% bonus at the top of the category vulnerability they discover.

“This is an unprecedented fully Apple supported iOS security research platform,” Krstić said at the conference. “We want to attract exceptional researchers who have been focused on other platforms,” he added.

It was initially launched by Apple in 2016 and the company includes the only iOS as a part of the program, several researchers complained Apple failing to include other operating systems in the program, finally, the announcement came now.

The massive expansion of the Apple’s bug bounty program welcomed by bug bounty hunters and security researchers, Wardle who found many critical vulnerabilities in Apple products said that “Sure this is a win for Apple, but ultimately this a huge win for Apple’s end users.”

Sponsored:  â€“ Manage all the Endpoint networks from a single Console.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity course online to keep yourself updated.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Dell Enterprise SONiC Flaw Let Attackers Hijack the System

Dell Technologies has disclosed multiple critical security vulnerabilities in its Enterprise SONiC OS, which...

Amazon Confirms Employee Data Breach Via Third-party Vendor

Amazon has confirmed that sensitive employee data was exposed due to a breach at...

10 Best DNS Management Tools – 2025

Best DNS Management Tools play a crucial role in efficiently managing domain names and...

Sweet Security Announces Availability of its Cloud Native Detection & Response Platform on the AWS Marketplace

Customers can now easily integrate Sweet’s runtime detection and response platform into their AWS...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Dell Enterprise SONiC Flaw Let Attackers Hijack the System

Dell Technologies has disclosed multiple critical security vulnerabilities in its Enterprise SONiC OS, which...

Amazon Confirms Employee Data Breach Via Third-party Vendor

Amazon has confirmed that sensitive employee data was exposed due to a breach at...

Researchers Detailed Credential Abuse Cycle

Cybercriminals exploit leaked credentials, obtained through various means, to compromise systems and data, enabling...