An exploit that allows full control of the device that installs with no user interaction, zero-click, and is persistent even after rebooting or power cycling the device.
Also, max payout has been bumped to $1.5m which is a pretty big change. Most of this was announced a few months ago, they are just making good on a previous announcement at this point.
I heard a rumor that Apple has never paid out any money in their invite-only bug bounty days. This 2018 article seems to suggest that is true. Does anyone have any data to the contrary?
Critically, there's no information about whether reporters are allowed to disclose, which usually means that Apple is going to hide any seriously damaging vulnerabilities...
> Not disclose the issue publicly before Apple releases the security advisory for the report. (Generally, the advisory is released along with the associated update to resolve the issue). See terms and conditions.
Amazon: https://aws.amazon.com/security/vulnerability-reporting/
Netflix: https://help.netflix.com/en/node/6657
Google: https://www.google.com/about/appsecurity/programs-home/
Microsoft: https://www.microsoft.com/en-us/msrc/bounty
More: https://www.ubuntupit.com/best-bug-bounty-programs-on-intern...