The Apple Security Bounty program, launched in 2016, is intended to reward security researchers for discovering vulnerabilities in Apple’s products and services. However, a recent case in which a researcher received only $1,000 for a critical vulnerability has sparked heated discussion in the community, raising questions about the fairness of payouts and the program’s transparency.
The Case of RenwaX23
A researcher under the pseudonym RenwaX23 reported a vulnerability in the Safari browser, classified as Universal Cross-Site Scripting (UXSS). This type of vulnerability allows an attacker to impersonate a user and gain access to their data, including iCloud and the iOS camera. The vulnerability, registered as CVE-2025-30466, received a 9.8 out of 10 rating on the CVSS scale, indicating its critical nature. Apple fixed the issue in the Safari 18.4 update released in March 2025 alongside iOS/iPadOS 18.4 and macOS 15.4. However, RenwaX23 received only $1,000 for the discovery.
Why Was the Payout So Low?
Apple determines reward amounts based on several factors:
In RenwaX23’s case, the low payout was likely due to the significant user interaction required, which Apple deemed less critical in real-world exploitation scenarios. However, this caused dissatisfaction, as a vulnerability rated 9.8 is considered extremely serious.
Issues with the Apple Security Bounty Program
The Apple Security Bounty program offers payouts ranging from $500 to $2 million depending on the type of vulnerability and its impact. For example, access to iCloud data can yield up to $100,000, while compromising the XNU kernel or Secure Enclave can bring up to $1.5 million, with bonuses up to $2 million for bugs in beta versions or Lockdown Mode. Despite these high advertised figures, researchers often face challenges:
These problems have led to criticism of the program. Some researchers, frustrated by low payouts or lack of response, prefer to sell vulnerabilities on the “gray market” or publish them without notifying Apple, which can pose risks to users’ security.
The Role of Researchers and the Importance of the Program
Security researchers play a crucial role in ensuring the safety of Apple products by discovering vulnerabilities before attackers can exploit them. Since 2016, Apple has paid about $20 million through the Security Bounty program, with an average payout of $40,000 in the “Products” category, and over 20 vulnerabilities earning researchers more than $100,000. However, the RenwaX23 case highlights that even critical vulnerabilities can be undervalued.
Apple publishes information about discovered vulnerabilities in its updates, such as macOS Sequoia 15.6, including the CVE number and researcher name. This ensures recognition, but not always fair financial reward. For example, a team of five researchers received $288,500 for 55 vulnerabilities, including 11 critical ones, which could have allowed attackers to compromise iCloud or enterprise tools.
How Can the Program Be Improved?
The community suggests several steps to improve the Apple Security Bounty program:
Apple has already taken steps toward improvement, launching the Apple Security Research website in 2022 with detailed payout categories and starting a Private Cloud Compute program offering up to $1 million for vulnerabilities in cloud AI systems.
month
week
day