Overview
- Apple set the $2 million tier for exploit chains that achieve goals comparable to high-end mercenary spyware attacks.
- Bonus pathways for Lockdown Mode bypasses and vulnerabilities found in beta software can elevate total awards to more than $5 million.
- Expanded categories include $1 million for broad unauthorized iCloud access, up to $1 million for wireless proximity exploits, up to $300,000 for one-click WebKit sandbox escapes, and $100,000 for a complete Gatekeeper bypass on macOS.
- New Target Flags will let researchers objectively demonstrate exploitability in defined categories to qualify for faster awards.
- The updated rules take effect in November 2025, and Apple says it has paid $35 million to more than 800 researchers since launching the program in 2020.