Apple will pay up to $2 million bug bounty reward appeared first on MacDailyNews. Apple will pay up to $2 million bug bounty reward appeared first on MacDailyNews. Apple will pay up to $2 million bug bounty reward appeared first on MacDailyNews. Apple will pay up to $2 million bug bounty reward appeared first on MacDailyNews.
At the Hexacon offensive security conference in Paris on Friday, Apple VP of security engineering and architecture Ivan Krstić revealed a new maximum payout of $2 million for a chain

Apple logo with security lock

At the Hexacon offensive security conference in Paris on Friday, Apple VP of security engineering and architecture Ivan Krstić revealed a new maximum payout of $2 million for a chain of software exploits vulnerable to spyware abuse.

Lily Hay Newman for Wired:

In addition to individual payouts, the company’s bug bounty also includes a bonus structure, adding additional awards for exploits that can bypass its extra secure Lockdown Mode as well as those discovered while Apple software is still in its beta testing phase. Taken together, the maximum award for what would otherwise be a potentially catastrophic exploit chain will now be $5 million. The changes take effect next month.

“We are lining up to pay many millions of dollars here, and there’s a reason,” Krstić tells WIRED. “We want to make sure that for the hardest categories, the hardest problems, the things that most closely mirror the kinds of attacks that we see with mercenary spyware — that the researchers who have those skills and abilities and put in that effort and time can get a tremendous reward.”

Apple says that there are more than 2.35 billion of its devices active around the world. The company’s bug bounty was originally an invite-only program for prominent researchers, but since opening to the public in 2020, Apple says that it has awarded more than $35 million to more than 800 security researchers. Top-dollar payouts are very rare, but Krstić says that the company has made multiple $500,000 payouts in recent years.

“You can say, well, that seems like a very large effort to protect only that very small number of users that are being targeted by mercenary spyware, but there is just this incontrovertible track record described by journalists, tech companies, and civil society organizations that these technologies are constantly being abused,” Krstić says. “And we feel a great moral obligation to defend those users. Despite the fact that the vast majority of our users will never be targeted by anything like this, this work that we did will end up increasing protection for everyone.”


MacDailyNews Take: Have at it, bug busters!



Please help support MacDailyNews — and enjoy subscriber-only articles, comments, chat, and more — by subscribing to our Substack: macdailynews.substack.com. Thank you!

Support MacDailyNews at no extra cost to you by using this link to shop at Amazon.

The post Apple will pay up to $2 million bug bounty reward appeared first on MacDailyNews.

original link


You may also be interested in this

Apple investors reject pr…

Apple is holding its annual shareholder meeting today as investors vote on several proposals and hear updates from CEO Tim Cook. Most notably, Apple shareholders rejected an outside proposal calling

Google finally brings Chr…

Tab groups, a feature of Google's Chrome desktop browser for years, finally made its way to the iPhone and iPad version. (via Cult of Mac - Apple news, rumors, reviews

Data leak affecting every…

Hard as it may be to imagine, the massive data leak – which appears to include the personal data of everyone in the US, UK, and Canada – was even

Apple will reportedly ope…

Apple is planning to open up the large language models that power Apple Intelligence AI features so developers can use them in their own apps, reports Bloomberg. According to its

Apple releases iOS 18.3.1…

Apple officially announced the iPhone 16e today, replacing the iPhone SE and iPhone 14 with a $599 model that supports Apple Intelligence. Following the announcement, Apple has also posted the

AirPods Pro 3 said to get…

Apple’s AirPods Pro 3 are set to debut- likely on September 9th – introducing a refined design and innovative features that elevate the wireless earbud experience. The upcoming earbuds promise

iPhone 16e is officially …

The iPhone 16e is now on sale in major markets worldwide, providing a more affordable way to experience Apple Intelligence. (via Cult of Mac - Apple news, rumors, reviews and

Study reveals top 20 most…

Ahead of World Password Day on May 4, NordPass has released a report showing that “password habits die hard” with a list of the most used passwords in the US
X

A whimsical homage to the days in black and white, celebrating the magic of Mac OS. Dress up your blog with retro, chunky-grade pixellated graphics to evoke some serious computer nostalgia. Supports a custom menu, custom header image, custom background, two footer widget areas, and a full-width page template. I updated Stuart Brown's 2011 masterpiece to meet the needs of the times, made it responsive , got dark mode, custom search widget and more.You can download it from tigaman.com, where you can also find more useful code snippets and plugins to get even more out of wordpress.