Apple iPhone Bug Bounties Hit $2 Million – Hackers Could Earn More Than a CEO

Apple’s bug bounty program now offers up to $5 million for zero-click iPhone exploits, quadrupling previous maximums

C. da Costa Avatar
C. da Costa Avatar

By

Our editorial process is built on human expertise, ensuring that every article is reliable and trustworthy. AI helps us shape our content to be as accurate and engaging as possible.
Learn more about our commitment to integrity in our Code of Ethics.

Image credit: Wikimedia

Key Takeaways

Key Takeaways

  • Apple doubles maximum bug bounty to $2 million for zero-click iPhone exploits
  • Company paid $35 million to 800-plus researchers since opening program in 2020
  • Target Flags system streamlines exploit verification and speeds researcher payment processes

Apple just made finding iPhone exploits more lucrative than most people’s annual salaries. The company doubled its maximum bug bounty reward from $1 million to $2 million for zero-click vulnerabilities—attacks that compromise your device without any interaction from you. Stack the bonus multipliers, and researchers could pocket over $5 million for a single discovery. That’s not just raising the stakes; that’s declaring war on the black market exploit economy.

The New Bounty Breakdown

Your phone’s security vulnerabilities now carry price tags that would make lottery winners jealous. Proximity-based exploits requiring just one click can earn researchers up to $1 million, quadruple the previous ceiling. Physical device attacks max out at $500,000, while WebKit code execution chained with sandbox escapes nets $300,000. Even macOS Gatekeeper bypasses command $100,000—money previously reserved for Hollywood fantasies.

Follow the Money Trail

Since opening the program beyond invitation-only status in 2020, Apple has cut checks totaling $35 million across 800-plus security researchers. Multiple $500,000 payments have already been made, with the average payout hovering around $40,000. Apple VP Ivan Krstić told Wired in a recent interview that top-tier rewards remain “rare” but stressed their necessity as a counterweight to mercenary spyware developers who offer similar sums for weaponized exploits.

The Target Flags Revolution

Beyond the headline numbers, Apple’s rolling out Target Flags—objective markers embedded within operating systems that let researchers demonstrate exploit effectiveness without lengthy back-and-forth verification. Think achievement badges for vulnerability hunters. This streamlined approach means faster evaluation times and payments that can arrive even before public security patches, incentivizing responsible disclosure over underground sales.

This financial arms race isn’t just about protecting iPhones—it’s about redirecting elite hacking talent toward defending the devices in your pocket rather than compromising them. When your personal data becomes the battlefield, Apple’s betting that outbidding the bad guys makes everyone safer.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →