
True to the announcement it made last August at the Black Hat security conference in Las Vegas, Apple officially launched its bug bounty program on Friday for all researchers.
Until now, the company has only run bug bounty programs for select researchers and only accepted security bugs for iOS.
With its new program, Apple will accept vulnerability reports for a much broader range of products including iPadOS, macOS, tvOS, watchOS, and iCloud.
Additionally, the company has also increased the maximum reward, from $200,000 to $1,500,000, depending on the complexity and severity of the vulnerability chain.
Along with the official announcement of its new program, Apple also published a new page on its website that details the bug bounty program rules for major bugs, as well as a breakdown of the rewards that will be given to researchers depending on their findings.
These are pretty strict rules, which set the bar high for those who want to earn the top rewards. In order for a researcher to be eligible for the top prizes and bonuses, they must submit clear reports. These include:
- Detailed description of the problems discovered.
- Any conditions and steps can have an impact on the system.
- A reliable finding for the discovery it mentions.
- Enough information for Apple to be able to reproduce the problem.
Security bugs that are innovative, impact multiple platforms, work with the latest hardware and software, and affect sensitive system components will give a researcher a better chance of winning the top $1.5 million reward .
Furthermore, vulnerabilities found in beta will be rewarded just as well. Apple says it will add a 50% bonus on top of the stated payout for any bug discovered in a beta version.
The reason why bugs in beta versions yield high rewards is because these bug reports allow Apple to fix significant security flaws before they reach production versions of its software, where they will affect billions of devices.
Apple's bug bounty program will also give a 50% bonus for regression bugs. These are bugs that Apple had previously fixed in older versions of its software but have been reintroduced into the code at a later stage.
Vulnerabilities that allow for no-click or single-click attacks are the ones that will bring in the most money for researchers, but Apple requires the full exploit chain for these types of bugs.
If, for example, one of these attacks uses three different bugs linked together, the researcher should submit the full exploit chain that incorporates all three bugs, not just one, if they want to earn the maximum reward.
For more details about Apple's new bug bounty program, visit the company's official site .
