Tag: zero-click RCE vulnerabilities

Apple now offers $2 million for zero-click RCE vulnerabilities
News

Apple now offers $2 million for zero-click RCE vulnerabilities

Apple has announced a significant revamp and expansion of its bug bounty program, which includes additional research areas, a more transparent payment structure, and a doubling of maximum awards. Apple has given $35 million to 800 security researchers since the program's inception in 2020, and the corporation has paid $500,000 for some of the reports that have been filed. For disclosing vulnerabilities that potentially result in zero-click (no user interaction) remote compromise, akin to mercenary spyware assaults, the highest reward has been upped to $2 million. However, the bonus system has the potential to pay out up to $5 million. This payout is the biggest of any bounty program we know of and is unprecedented in the industry. Additionally, Apple stated that our bonus system,...