Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
What information are we talking about being worried about?

Despite all of our concerns about it, one way or another it seems like those that want to know have figured out who we are, where we are, where we go, what we do, what we buy, our SS #, all our vitals and family tree, our credit risk, net worth, assets on hand, if you're sick, if you're pregnant .. on and on and on..

What info are we protecting exactly?
Just credit card numbers from fraud I guess?

Don't misunderstand me -- I want to protect it all!
It just seems like we are largely running plays after the game already ended.
 
Last edited:
Great program, worst execution. There have been so many exploits that have been disclosed and those who find it do not get even remotely what Apple promises them. This is the reason many exploits remain hidden and get sold to higher bidders
Are some exploits more dangerous (worth more) than others? Genuinely curious
 
  • Like
Reactions: JohnWick1954
I think the overall culture shift at Apple is now for others to fix things. A bug bounty program is great as a supplement, but not releasing high quality software from the get go for what Apple charges seems to be mitigating that extra price you pay for a smooth operation.
 
  • Like
Reactions: maxoakland
Funny when Apple increases bug bounties and yet people still just find reason to complain.

Waiting for the day Apple cures cancer, charges $99 for the cure and people say it’s too much.

What I always found funny was companies like Zerodium offering huge payouts for exploits. What’s to stop me from collecting money from Zerodium and then telling my friend about the exploit so they can collect from Apple? How would Zerodium (or NSO or other bad actor) even know we did this? We get paid twice for the same exploit.
 
  • Like
Reactions: Jumpthesnark
Funny when Apple increases bug bounties and yet people still just find reason to complain.

Waiting for the day Apple cures cancer, charges $99 for the cure and people say it’s too much.

What I always found funny was companies like Zerodium offering huge payouts for exploits. What’s to stop me from collecting money from Zerodium and then telling my friend about the exploit so they can collect from Apple? How would Zerodium (or NSO or other bad actor) even know we did this? We get paid twice for the same exploit.

Apple has nothing to do with curing cancer! Maybe if Apple put more resources dealing with iOS bugs then people would be more excited.
 
100%. They've routinely stolen ideas from Android, iOS Jailbreak tweaks/functions as well as from their own Developers (sherlocking).

It's hilarious to me when people go bananas pointing out others copying from Apple with the unbelievably old and tired "Redmond, start your photocopiers!" gag.

View attachment 2566192
Truth is stranger than fiction.
 
  • Like
Reactions: maxoakland
CompanyProgram NameMax Reward (USD)Notes
AppleApple Security Bounty$2,000,000For zero-click spyware exploit chains (effective Nov 2025); previously $1M.
GoogleVulnerability Reward Program$1,500,000For full-chain zero-click RCE in Android; up to $3.1M for Chrome sandbox escapes.
MicrosoftMicrosoft Bounty Programs$250,000For critical RCE in Hyper-V or Azure; varies by product (e.g., $100K+ for Edge).
MetaMeta Bug Bounty$300,000For mobile RCE exploits; focuses on privacy/compromise in apps like Facebook/Instagram.
IntelIntel Bug Bounty$100,000For critical hardware RCE; lower for software-only issues.

Honestly I trust none of them. Fully, no way.
Yarp. Apple says they'll keep our data private, but it's only a matter of time. Remember way back when, when Google used to say, "Don't be evil"? Big Tech.:rolleyes: Birds of a feather...😗🎶
 
What prevents Apple from secretly bidding on exploits being auctioned on the open market? They have unlimited funds.

And how does someone even SELL an exploit to the “highest bidder?” Wouldn’t the seller have to prove the exploit works, thus revealing critical aspects of the exploit?
 
  • Like
Reactions: JohnWick1954
Yarp. Apple says they'll keep our data private, but it's only a matter of time. Remember way back when, when Google used to say, "Don't be evil"? Big Tech.:rolleyes: Birds of a feather...😗🎶
Only a matter of time? SCA passed 39 years ago.

Screenshot 2025-10-10 at 17.27.20.png
 
Remember when that guy found that exploit and Apple refused to pay him the bug bounty? Why would anyone trust them to follow through?
Apple would have a clause in this program for exploits already found but not yet published fixes for—obviously they wouldn't advertise these to anyone. If I was to bet I'd say this is what happened that guy but he couldn't accept it—found an unfixed exploit and reported it and Apple told him they had already found it. I don't see what Apple would have to gain, unless they had a rouge employee. You would imagine if they did they would have pressed charges.
 
Last edited:
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.