
Apple announced at Hexacon 2025, the top global offensive security conference, that it will double its highest security bounty to $2 million. This makes Cupertino the most generous company that offers an award for unearthing vulnerabilities, and it’s even offering top-up bonuses that can see security experts earning more than $5 million for uncovering exploits. According to Apple’s Security Research blog, it has already awarded over $35 million to more than 800 security researchers since 2020, bringing the average award to $43,750. It even claimed that multiple individuals have received $500,000 in rewards.
The top $2-million award is reserved for those who discover sophisticated exploit chains similar to what mercenary spyware attacks exploit. Beyond that, there’s also a bonus system for those who can break Apple’s Lockdown Mode secure environment and vulnerabilities in its beta software, bringing the potential payout to over $5 million. There are also smaller awards, like $1 million for those who can crack broad iCloud security and those who can create a wireless proximity attack using radio, up to $300,000 to anyone who develops a one-click WebKit sandbox escape mechanism, and $100,000 to those who can bypass Gatekeeper on macOS.