Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Does Apple pay bug bounties?


They claim to, but they drag their feet, demand terms most researchers find so unacceptable as to be a bit immoral (the point of "responsible disclosure" isn't, in fact, to hold secrets from the public arbitrarily long), and often end up paying only a fraction of what was expected, if anything.

https://pxlnv.com/linklog/apple-bug-bounty-troubles/

https://www.marketplace.org/shows/marketplace-tech/looking-f...

https://mjtsai.com/blog/2021/07/13/more-trouble-with-the-app...


Your links are all from 2021. I remember there was a lot of criticism at the time and so they updated their bug bounty program which quite a number of changes:

https://security.apple.com/blog/apple-security-bounty-upgrad...

Would be interesting to see if it made a difference.


The vibe I got talking to people like Mark Dowd about this is that they're running something closer to an exploit bounty program, and it's pretty focused on patterns of vulnerabilities common to some pretty specific threat actors.


Yes, they do.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: