Apple takes security of its devices very serious and to improve its systems it initiated the Apple Security Bounty program in 2022. The Apple Security Bounty program provides an avenue for Ethical hackers to find and report vulnerabilities within Apple products, and provides security researchers very large cash rewards.
Rewards start from a minimum reward of $5,000 and can go up to an impressive $2 million (or an Estimated ₹17.5 crore). With this amount being available from Apple, the Apple bug bounty is one of the most lucrative in the Technology world.
Apple specified Five categories of bounty payouts. In each category, Apple pays the different reward values depending on the severity level of the issue.
For attacks using physical access, the hacker needs to have physical access to the device to be able to exploit it. For example, bypassing the lock screen could earn as much as $100,000, or extracting user data from a locked phone could be as high as $250,000.
Hacking via user installed apps, the hacker must exploit the vulnerabilities via apps the user installs. The rewards for this category can vary from $5,000 to as high as $150,000.
This is unauthorized access or elevation of privileges via user interaction. The one-click data access or elevation of privileges could earn up to $250,000.
These attacks are executed without user action and fall into the “zeroclick” category. Hackers can earn either $1 million for bypassing Apple’s Kernel PAC protections. There are rewards available for other attacks in this category.
Hackers can earn approximately $150,000 by targeting data stored on Apple’s private cloud from a privileged network position. If executed remotely as an attacker, hackers can earn $1 million, or $2 million (₹17.5 crore) in total, for bypassing the protections in Lockdown Mode.
Apple is using this bounty program as a means of making accessing iPhones and other devices as safe as possible. They are trying to get as many ethical hackers interested in finding and reporting serious flaws. If you have the capability, this is a great way to earn money.
Originally, Apple provides payouts to valid reports. Hackers must explain the contents of the bug to inform Apple and prove the impact of the bug. Apple then verifies, as appropriate and allows for a calculator of the payout amount.
Also Read: Meet the World’s Most Exclusive iPhone – Priced At Rs 42 Lakh