White hat hacker discovers critical vulnerability in Safari: Apple pays him only $1,000

July 31, 2025  20:40

The Apple Security Bounty program, launched in 2016, is intended to reward security researchers for discovering vulnerabilities in Apple’s products and services. However, a recent case in which a researcher received only $1,000 for a critical vulnerability has sparked heated discussion in the community, raising questions about the fairness of payouts and the program’s transparency.

The Case of RenwaX23

A researcher under the pseudonym RenwaX23 reported a vulnerability in the Safari browser, classified as Universal Cross-Site Scripting (UXSS). This type of vulnerability allows an attacker to impersonate a user and gain access to their data, including iCloud and the iOS camera. The vulnerability, registered as CVE-2025-30466, received a 9.8 out of 10 rating on the CVSS scale, indicating its critical nature. Apple fixed the issue in the Safari 18.4 update released in March 2025 alongside iOS/iPadOS 18.4 and macOS 15.4. However, RenwaX23 received only $1,000 for the discovery.

Why Was the Payout So Low?

Apple determines reward amounts based on several factors:

  • User interaction required: If exploiting the vulnerability requires active user actions, the priority is lowered. In the case of RenwaX23’s vulnerability, some researchers believe too many user actions were needed to activate the exploit.
  • Number of affected users: Vulnerabilities impacting a large number of users receive higher payouts.
  • Access level: Vulnerabilities that provide full access to the system or data are rated higher.
  • Report quality: A detailed report with clear reproduction steps and a working exploit increases the chance of a higher reward.

In RenwaX23’s case, the low payout was likely due to the significant user interaction required, which Apple deemed less critical in real-world exploitation scenarios. However, this caused dissatisfaction, as a vulnerability rated 9.8 is considered extremely serious.

Issues with the Apple Security Bounty Program

The Apple Security Bounty program offers payouts ranging from $500 to $2 million depending on the type of vulnerability and its impact. For example, access to iCloud data can yield up to $100,000, while compromising the XNU kernel or Secure Enclave can bring up to $1.5 million, with bonuses up to $2 million for bugs in beta versions or Lockdown Mode. Despite these high advertised figures, researchers often face challenges:

  • Low payouts: Another researcher, Taiko_soup, reported receiving only $5,000 for a vulnerability that, by Apple’s own criteria, should have earned $50,000. This points to a lack of transparency in assessment.
  • Long review times: Some researchers wait months or even years for decisions, especially for complex or system-level vulnerabilities.
  • Lack of communication: Apple often limits feedback, leaving researchers without explanations for why their report did not receive the expected reward.

These problems have led to criticism of the program. Some researchers, frustrated by low payouts or lack of response, prefer to sell vulnerabilities on the “gray market” or publish them without notifying Apple, which can pose risks to users’ security.

The Role of Researchers and the Importance of the Program

Security researchers play a crucial role in ensuring the safety of Apple products by discovering vulnerabilities before attackers can exploit them. Since 2016, Apple has paid about $20 million through the Security Bounty program, with an average payout of $40,000 in the “Products” category, and over 20 vulnerabilities earning researchers more than $100,000. However, the RenwaX23 case highlights that even critical vulnerabilities can be undervalued.

Apple publishes information about discovered vulnerabilities in its updates, such as macOS Sequoia 15.6, including the CVE number and researcher name. This ensures recognition, but not always fair financial reward. For example, a team of five researchers received $288,500 for 55 vulnerabilities, including 11 critical ones, which could have allowed attackers to compromise iCloud or enterprise tools.

How Can the Program Be Improved?

The community suggests several steps to improve the Apple Security Bounty program:

  • Transparency: Clearer evaluation criteria and explanations for payout decisions.
  • Faster response: Reducing the time required to review reports and fix vulnerabilities.
  • Fair payouts: Accounting for the real-world risk of vulnerabilities, even those requiring user interaction.
  • Support for researchers: Expanding the Security Research Device program, which provides special iPhones for testing, and improving communication.

Apple has already taken steps toward improvement, launching the Apple Security Research website in 2022 with detailed payout categories and starting a Private Cloud Compute program offering up to $1 million for vulnerabilities in cloud AI systems.


 
 
 
 
  • Archive