Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    Top iOS Bug Bounty Award Hits $1.5M

    Written by

    Sean Michael Kerner
    Published September 30, 2016
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The market for iOS bug bounty rewards now stands at an all-time high of $1.5 million, thanks to an increased payout schedule from Zerodium. On Sept. 29, the company updated its bug bounty payout ranges, increasing the top iOS reward, which previously stood at $1 million.

      Zerodium is offering the $1.5 million iOS bug bounty award for a remote jailbreak on the recently released iOS 10.

      In September 2015, Zerodium announced that it would award a $1 million prize for a browser-based, untethered jailbreak of Apple’s iOS 9 mobile operating system. The following month, Zerodium revealed that it had received a winning submission, which it awarded the $1 million prize.

      The newly updated Zerodium payout schedule, which includes bugs for operating systems, browsers, plug-ins, servers, applications and mobile devices, is not a point-in-time contest, but a year-round effort to solicit bug submissions from security researchers. Zerodium’s previous $1 million prize for an iOS bug was for a time-limited contest. The regular going rate for the top iOS bounty at Zerodium prior to Sept. 29 was in fact $500,000.

      At $1.5 million, Zerodium’s top iOS bug bounty is significantly higher than Apple’s own top bug bounty, which stands at $200,000. It was at the Black Hat USA 2016 event in August that Ivan Krstic, head of Apple security engineering and architecture, formally announced the debut of his company’s bug bounty program.

      Apple’s top bug bounty award for $200,000 is for secure boot firmware components on iPhone devices, which is not the area that Zerodium is focused on.

      “For the record, @Zerodium iOS bounty does NOT compete with @Apple as we focus on browsers+kernel while they focus on secure boot and enclave,” Chaouki Bekrar, founder of Zerodium, wrote in a Twitter message.

      The market for high-paying iOS bug bounties has become increasingly active in recent months. Security firm Exodus Intelligence announced in August that it will offer researchers up to $500,000 for a zero-day iOS vulnerability.

      Trend Micro’s Zero Day Initiative (ZDI) is also offering a large bug bounty for iOS. At the upcoming mobile Pwn2Own event—being held Oct. 26-27 at the PacSec Security Conference in Tokyo—ZDI is offering a $250,000 bounty for an iOS zero-day. The ZDI Pwn2Own iOS bug bounty has a very specific target though: successfully forcing an iPhone to unlock.

      Payout for Android Bugs Increase Too

      Not only did Zerodium increase the top payout for an iOS bug, but the company also increased its top payout for Google’s Android. On Sept. 29, Zerodium increased its bounty for an Android 7 remote jailbreak from $100,000 to $200,000. As it turns out though, Google’s top bug bounty prize for Android is the same amount. Google is running the Project Zero bug bounty program until March 14, 2017, which offers a top prize of $200,000.

      While the top prizes for iOS and Android vulnerabilities are continuing to go higher, it’s important to note that the average bug bounty payout is far less than those figures. Bug bounty firm Bugcrowd’s 2016 State of the Bug Bounty report found that the average bug bounty payout is $505.79.

      At the high end of the spectrum, Google and Apple have both invested heavily to secure their respective mobile operating systems from remote jailbreaks. The amount of time and effort required to bypass those systems is a nontrivial matter, and the high payouts are a reflection of that. On the other end of the spectrum, there is still a lot of “low hanging fruit,” with bugs of all sorts that security researchers can more easily find in applications from various vendors.

      While not every vulnerability is worth $1.5 million, bugs do have value, and rewarding researchers for finding them will continue to be a growing business for years to come.

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.