That’s right! It pays to hack.
First announced back in August this year, Apple has finally opened the doors of its previously invite-only security bounty programme to the world. The best part? There’s a US$ 1.5 million dollar bounty for those who find the most serious security issues in Apple’s system. This is a 500,000 dollar increase from the 1 million dollars initially offered to select security researchers if they are able to pinpoint vulnerabilities in iPhones and Macs back in August.
While Apple’s OS has generally been regarded as one of the safest OS around, it is not without its flaws. Case in point, a vulnerability earlier this year locked iPhone users who didn’t update to iOS 13.3 out of their devices. And this is just one example of security flaws in Apple’s supposedly safer ecosystem. To be fair, there is no system that is completely 100% secure. Regardless though, Apple wants to minimize the threat of a malicious attack on its devices, and this is where the Apple Bug Bounty Program comes in.
Now it’s worth noting that Apple isn’t the only company that offers bounties for ethical hackers to find vulnerabilities in it’s system. Apple is however offering some of the highest bounties out there. So how does it work exactly?
Well, for one, the issues found have to be on the “latest publicly available versions of iOS, iPadOS, macOS, tvOS, or watchOS with a standard configuration, and where relevant, on the latest publicly available hardware,”. Okay, fair enough.
Here’s a breakdown of the bounty payout:
- iCloud
- Unauthorized access to iCloud account data on Apple Servers ($100,000)
- Device attack via physical access
- Lock screen bypass ($100,000)
- User data extraction ($250,000)
- Device attack via user-installed app
- Unauthorized access to sensitive data ($100,000)
- Kernel code execution ($150,000)
- CPU side channel attack ($250,000)
- Network attack with user interaction
- One-click unauthorized access to sensitive data ($150,000)
- One-click kernel code execution ($250,000)
- Network attack without user interaction
- Zero-click radio to kernel with physical proximity ($250,000)
- Zero-click unauthorized access to sensitive data ($500,000)
- Zero-click kernel code execution with persistence and kernel PAC bypass ($1,000,000)
The bounty can be divided into many categories with the smallest payout being US$100,000 for those who can provide a report on the unauthorized access to iCloud account data on Apple servers. The biggest and most eyebrow raising payout is US$1000000 (1 million dollars) for “a zero-click kernel code execution with persistence and kernel PAC bypass,”. What exactly does that mean? I have no idea. That’s probably why I won’t be becoming a millionaire anytime soon but if you do, by all means, give it a shot!
Email your report directly to [email protected] and see how that works out for you.




