- Apple TV+ is ₹99/month after free trial. One subscription per Family Sharing group. Offer is valid for 3 months after eligible device activation. Plan automatically renews until cancelled. Restrictions and other terms apply. Game controllers work with select games and are.
- Browse, purchase, and download apps for your iPhone, iPad, iPod touch, Mac, Apple Watch, or Apple TV in the App Store. Learn how to use the App Store. Build, battle, explore, and more. Discover more than 100 exclusive single-player and multiplayer games with no ads or in-app purchases.
As part of Apple's commitment to security, we reward researchers who share with us critical issues and the techniques used to exploit them. We make it a priority to resolve confirmed issues as quickly as possible in order to best protect customers. Apple offers public recognition for those who submit valid reports, and will match donations of the bounty payment to qualifying charities.*
We would like to show you a description here but the site won't allow us. The members of our Apple Support Community can help answer your question. Or, if someone's already asked, you can search for the best answer. Tell us how we can help. Answer a few questions and we'll help you find a solution.
Eligibility
In order to be eligible for an Apple Security Bounty, the issue must occur on the latest publicly available versions of iOS, iPadOS, macOS, tvOS, or watchOS with a standard configuration and, where relevant, on the latest publicly available hardware or the Security Research Device. These eligibility rules are meant to protect customers until an update is available, ensure Apple can quickly verify reports and create necessary updates, and properly reward those doing original research. Researchers must:
- Be the first party to report the issue to Apple Product Security.
- Provide a clear report, which includes a working exploit (detailed below).
- Not disclose the issue publicly before Apple releases the security advisory for the report. (Generally, the advisory is released along with the associated update to resolve the issue). See terms and conditions.
Issues that are unknown to Apple and are unique to designated developer betas and public betas, including regressions, can result in a 50% bonus payment. Qualifying issues include:
- Security issues introduced in certain designated developer beta or public beta releases, as noted in their release notes. Not all developer or public betas are eligible for this additional bonus.
- Regressions of previously resolved issues, including those with published advisories, that have been reintroduced in certain designated developer beta or public beta release, as noted in their release notes.
Vatican Site Officiel
Bounty Categories
Bounty payments are determined by the level of access or execution achieved by the reported issue, modified by the quality of the report. A maximum amount is set for each category. The exact payment amounts are determined after review by Apple. All security issues with significant impact to users will be considered for Apple Security Bounty payment, even if they do not fit the published bounty categories. Apple Security Bounty payments are at Apple's discretion.
Topic | Maximum Payout | |
---|---|---|
iCloud | Unauthorized access to iCloud account data on Apple Servers | $100,000 |
Device attack via physical access | Lock screen bypass | $100,000 |
User data extraction | $250,000 | |
Device attack via user-installed app | Unauthorized access to sensitive data** | $100,000 |
Kernel code execution | $150,000 | |
CPU side channel attack | $250,000 | |
Network attack with user interaction | One-click unauthorized access to sensitive data** | $150,000 |
One-click kernel code execution | $250,000 | |
Network attack without user interaction | Zero-click radio to kernel with physical proximity | Macbook operating system. $250,000 |
Zero-click unauthorized access to sensitive data** | $500,000 | |
Zero-click kernel code execution with persistence and kernel PAC bypass | $1,000,000 |
Report and Payout Guidelines
The goal of the Apple Security Bounty is to protect customers through understanding both vulnerabilities and their exploitation techniques. Reports that include a basic proof of concept instead of a working exploit are eligible to receive no more than 50% of the maximum payout amount. Reports lacking necessary information to enable Apple to efficiently reproduce the issue will result in a significantly reduced bounty payment, if accepted at all.
A complete report includes:
- A detailed description of the issues being reported.
- Any prerequisites and steps to get the system to an impacted state.
- A reasonably reliable exploit for the issue being reported.
- Enough information for Apple to be able to reasonably reproduce the issue.
Maximizing Your Payout
To maximize your payout, keep in mind that Apple is particularly interested in issues that:
Apple Site Officiel Gratuit
- Affect multiple platforms.
- Impact the latest publicly available hardware and software.
- Are unique to newly added features or code in designated developer betas or public betas, including regressions, as noted on this page when available.
- Impact sensitive components.
- Are novel.
Additional Requirements
In addition to a complete report, issues that require the execution of multiple exploits, as well as one-click and zero-click issues, require a full chain for maximum payout. The chain and report must include:
- Both compiled and source versions.
- Everything needed to execute the chain.
- A sample non-destructive payload, if needed.
Official Apple Site
Sending Your Report
Send your report by email to product-security@apple.com. Whenever possible, encrypt all communications with the Apple Product Security PGP Key. Include all relevant videos, crash logs, and system diagnosis reports in your email. If necessary, use Mail Drop to send large files.
Example Payouts
View a list of example bounty payouts.
Terms and Conditions
Read the legal requirements for the Apple Security Bounty Program.