Close ad

Apple today officially launched its bug bounty program to the public, in which it offers a reward of up to one million dollars for the discovery of a serious security flaw in one of its operating systems or in iCloud. The company thus not only expanded the program, but also increased the rewards for finding errors.

Until now, it was possible to participate in Apple's bug bounty program only after receiving an invitation, and it only concerned the iOS system and related devices. Starting today, Apple will reward any hacker who finds and describes a security flaw in iOS, macOS, tvOS, watchOS, and iCloud.

In addition, Apple increased the maximum reward that it is willing to pay within the program, from the original 200 dollars (4,5 million crowns) to a full 1 million dollars (23 million crowns). However, it is possible to get a claim for this only on the assumption that the attack on the device will take place over the network, without user interaction, the error will concern the core of the operating system and meet other criteria. The discovery of other bugs – allowing, for example, to bypass the device's security code – is rewarded with sums in the order of hundreds of thousands of dollars. The program even applies to beta versions of the systems, but within those, Apple will increase the reward by another 50%, so it can pay out up to 1,5 million dollars (34 million crowns). An overview of all rewards is available <a href="https://cdn.shopify.com/s/files/1/1932/8043/files/200721_ODSTOUPENI_BEZ_UDANI_DUVODU__EN.pdf?v=1595428404" data-gt-href-en="https://en.notsofunnyany.com/">here</a>.

In order to be entitled to the reward, the researcher must describe the error properly and in detail. For example, the state of the system in which the vulnerability operates needs to be specified. Apple subsequently verifies that the error actually exists. Thanks to the detailed description, the company will also be able to release the relevant patch faster.

apple products

Next year even Apple will give selected hackers special iPhones for easier detection of security errors. The devices should be modified in such a way that it will be possible to gain access to the lower layers of the operating system, which currently only allows jailbreak or demo pieces of phones.

.