• Industry News
  • CXO Spotlight
  • AI
  • Enterprise Security

 Back to New Tab

Apple Doubles Top Bug Bounty to $2M in Spyware Arms Race

New Tab News Team
October 15, 2025
Industry News

Apple overhauls its bug bounty program, doubling the top reward for zero-click exploits to $2 million in an effort to combat mercenary spyware.

Credit: Outlever

In a major escalation against mercenary spyware, Apple is overhauling its bug bounty program, doubling its top reward for zero-click exploits to $2 million, with potential payouts topping $5 million. The company announced the changes at the Hexacon security conference in Paris, as reported by Wired.

  • A pricey deterrent: The move is a direct response to the growing threat from state-sponsored malware used to target high-profile individuals like journalists and dissidents. Apple says these are the only system-level iOS attacks it sees in the wild, and the higher payouts are designed to keep critical vulnerability research out of the hands of bad actors.

  • Upping the ante: The updated system, launching in November, features higher payouts across the board, with rewards for "one-click" remote attacks jumping to $1 million from $250,000. Apple is also offering $100,000 for a complete Gatekeeper bypass and $1 million for gaining unauthorized access to iCloud data, a vulnerability it says no one has successfully exploited to date. Since 2020, the company has paid over $35 million to researchers.

  • Capture the flag, get the cash: To improve its relationship with the research community, Apple is introducing "Target Flags," a system that allows hackers to objectively prove their exploits and get paid faster. The company will also donate one thousand iPhone 17s, which feature its new Memory Integrity Enforcement, to civil society groups that protect at-risk individuals.

Apple is putting its money where its mouth is, making a clear calculation that paying millions to white-hat hackers is cheaper than the damage a sophisticated spyware campaign can do to its reputation and user trust.

  • Also on our radar: Even as Apple shores up its current software, rumors are already swirling about the iPhone 18 Pro's potential new features. Looking further ahead, the company is also seeking researchers for a separate program focused on the security of its 2026 iPhone hardware.

Related content

Cyber Risk Accountability Moves Beyond Technical Teams To Executive Leadership

Muhammad Arshi Wasique, GM of MEA Operations at ThreatCure, reframes cyber risk as a financial tradeoff, pushing accountability from CISOs to CFOs and boards.

In Local Government, Cybersecurity Success Comes From Doing More With Less

Shane McDaniel, CIO for the City of Seguin, shows how municipal cybersecurity moves forward through resourcefulness, trust, and community when budgets and priorities collide.

New Oversight Frameworks Address Internal Fraud as Power Concentrates in Leadership

Srilakshmi Tariniganti, Technology Risk Manager at Sutherland, reframes AI risk around people, outlining oversight models that curb internal fraud by checking concentrated executive power.

You might also like

See all →

Apple Doubles Top Bug Bounty to $2M in Spyware Arms Race

Report says majority of employees embrace AI unsupervised, leaving companies vulnerable

New Report Says Workers and Execs Alike are Breaking Their Own Rules on AI Usage

Powered by Island.
ISLAND, All rights reserved ©