Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Samsung showed me its secret HDR10+ Advanced TV samples – and I’m almost sold

    November 8, 2025

    Starbucks barista’s side hustle brings in $1 million a month

    November 8, 2025

    A new Chinese AI model claims to outperform GPT-5 and Sonnet 4.5 – and it’s free

    November 8, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Apple now offers $2 million to fix zero-click RCE vulnerabilities
    Security

    Apple now offers $2 million to fix zero-click RCE vulnerabilities

    PineapplesUpdateBy PineapplesUpdateOctober 11, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Apple now offers  million to fix zero-click RCE vulnerabilities
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Apple now offers  million to fix zero-click RCE vulnerabilities

    Apple is announcing a major expansion and redesign of its bug bounty program, doubling the maximum payout, adding new research categories, and introducing a more transparent reward structure.

    Since the program began in 2020, Apple has awarded $35 million to 800 security researchers, with the company paying $500,000 for some reports submitted.

    The highest reward has been doubled to $2 million for reporting vulnerabilities that could lead to zero-click (no user interaction) remote compromise, similar to mercenary spyware attacks. However, payouts through the bonus system can be up to $5 million.

    “This is an unprecedented amount in the industry and the largest payout amount offered by any bounty program that we are aware of – and our bonus system, offering additional rewards for lockdown mode bypasses and vulnerabilities discovered in beta software, can more than double this bounty, bringing the maximum payout to over $5 million.” Apple said,

    Other payments enhanced or introduced under the new program plan include:

    • One-click (user interaction) remote attack – $1,000,000
    • Wireless Proximity Attack – $1,000,000
    • Mass unauthorized iCloud access – $1,000,000
    • WebKit exploit chain leading to unsigned arbitrary code execution – $1,000,000
    • Attack on locked device with physical access – $500,000
    • App Sandbox Escape – $500,000
    • One-Click WebKit Sandbox Escape – $300,000
    • macOS Gatekeeper complete bypass without any user interaction – $100,000
    • “Incentive award” of $1,000 for low-impact but legitimate reports.

    Apple comments that it has never received any reports demonstrating complete Gatekeeper bypass with no user interaction or widespread unauthorized iCloud access, so both of these bugs are high challenge points for bounty hunters.

    Additionally, Apple said it “has never seen a real-world zero-click attack executed entirely via wireless proximity,” referring to the $1M ‘Wireless Proximity’ prize, which was previously increased from $250,000.

    The range is also being expanded, now including Apple-developed chips such as the C1 and C1X modems and the N1 wireless chip.

    For 2026, Apple plans to distribute one thousand secure iPhone 17 devices to members of civil society organizations at high risk of being targeted by mercenary spyware.

    The same devices will power Apple Security Research Tools Program Next year, for which security researchers can apply till October 31.

    The tech giant hopes the increased rewards will have an additional impact on the development of sophisticated attack chains from spyware vendors, as researchers will have more incentive to find and report security issues.

    To protect its users from sophisticated spyware attacks, Apple implemented advanced security measures in iOS such as lockdown mode and memory integrity enforcementWhich makes it more expensive to develop and execute covert spyware attacks.


    PICS BAS Summit

    attend Breach and Attack Simulation Summit and experience future of security verificationHear from top experts and see how AI-powered BAS Changing breach and attack simulations.

    Don’t miss the event that will shape the future of your security strategy

    Apple fix million offers RCE vulnerabilities Zeroclick
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleIt’s not too late for Apple to get AI right
    Next Article Microsoft Office 2024 for Mac or PC is yours forever with one payment
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    Starbucks barista’s side hustle brings in $1 million a month

    November 8, 2025
    Startups

    As OpenAI hits 1 million business customers, could the AI ​​ROI trend finally change?

    November 7, 2025
    Startups

    One of the Best Apple Watches You Can Buy Isn’t Apple’s Latest (But It’s 30% Off)

    November 6, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    Samsung showed me its secret HDR10+ Advanced TV samples – and I’m almost sold

    November 8, 2025

    Starbucks barista’s side hustle brings in $1 million a month

    November 8, 2025

    A new Chinese AI model claims to outperform GPT-5 and Sonnet 4.5 – and it’s free

    November 8, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.