logo

Apple now offers $2 million for zero-click RCE vulnerabilities

ID: 4f000921-410a-5ebe-b453-39e68823b0cf

STIX ID: report--4f000921-410a-5ebe-b453-39e68823b0cf

Feed Name: Bleeping Computer

Date Published: 2025-10-10

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Apple unveiled a revamped bug bounty program with maximum rewards doubled to $2 million—and over $5 million with bonuses—for zero-click RCE and other high-impact findings, alongside expanded categories (e.g., wireless proximity, iCloud, WebKit) and clearer payout structures. The company will distribute secured iPhone 17 devices to high-risk civil society groups, feed its Security Research Device Program, and continue bolstering defenses like Lockdown Mode and Memory Integrity Enforcement to deter sophisticated spyware operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.