Apple Announces Bug Bounty Program
Apple announced the company will pay for vulnerabilities found in certain aspects of iOS and iCloud. Set for launch in September, the invitation only program will offer $25,000 to $200,000 within five years, but could be much lower. The program will be open to researchers who have previously made valuable vulnerability disclosures to Apple. However, Apple said it would not turn away new researchers if they provide "useful" disclosures.
The announcement came during a presentation by Apple’s head of security engineering and architecture, at the Black Hat security research conference in Las Vegas.
The program is limited to five bugs categories -- the most valuable category is worth up to $200,000 for vulnerabilities that compromise the secure boot firmware components.
To be eligible, researchers will need to provide a proof-of-concept on the latest iOS and hardware.
Google, Microsoft, and Facebook have bug bounty programmes in place for years.