Bug Bounties Reaching $500,000 For iOS Exploits


It seems this year bug bounties are getting really serious, especially on the secondary market involving exploit trading firms, not direct to the software producer or owner.

Bug Bounties Reaching $500,000 For iOS Exploits

$500,000 isn’t chump change and would be a good year for a small security team, especially living somewhere with a weaker currency. Even for a solo security researcher in the US or Europe that’s a serious wad of cash.

Chrome isn’t too far behind either with $150,000 payouts available.

Last week Apple made its belated entrance into the bug bounty market, announcing a top award of $200,000 for major flaws in iOS, but Cook & Co have been comprehensively outbid.

On Tuesday, exploit trading firm Exodus Intelligence said it is willing to pay $500,000 for a major flaw in iOS 9.3 and above – and the exploit to use it. Researchers can either take a lump sum or accept a smaller sum and quarterly payments until the exploit is found, which the company’s founder told The Reg could add up to even more.

“The majority of our clients are defensive vendors, penetration testers, and red/blue teams,” said Logan Brown, president of Exodus.

Apple exploits get the highest reward, reflective of their scarcity. Microsoft and Google’s bug bounty programs will also need to up their rewards to match Exodus’s prices.

A zero day in Google Chrome would earn a maximum of $150,000, 50 per cent more than the Chocolate Factory’s highest cash payout.


It looks like Apple devices are still the hot thing to go after with a serious lack of exploits available for new iOS versions. Even Apple themselves are offering $200,000

To get the maximum payout from Apple you’ll need to provide a flaw in the secure boot firmware that so irritated the FBI, while a crack that can extract confidential data protected by a phone or tablet’s secure enclave processor (SEP) will yield a prize of up to $100,000.

Meanwhile, finding a serious flaw in Redmond’s Edge browser is worth $125,000 to Exodus, dwarfing the $500 and $1,500 currently offered by Microsoft. There’s also $75,000 up for grabs if you can subvert the local privileges in Windows 10 and show how it’s done.

Exodus has said it’s happy to pay these bounties in check, wire transfer, Western Union, or Bitcoin.

Nevertheless, this is exactly the type of bidding war that major software companies didn’t want to see when they started doing bug bounties. Initially prices for vulnerabilities were set low, but are rising to meet market rates. Now security researchers are able to make a decent living practicing their craft.

As you can see, Exodus is offering multitudes more than the vendors themselves with a flaw in Edge going for $125,000 with Microsoft only offering a measly $1500.

It’s not what the software vendors wanted, but it’s what the public needs to expose serious flaws – they need to cough up and catch market rates though. If not the exploits may end up with governments that probably shouldn’t have them.

Source: The Register

Posted in: Apple, Exploits/Vulnerabilities

, ,


Latest Posts:


OWASP APICheck - HTTP API DevSecOps Toolset OWASP APICheck – HTTP API DevSecOps Toolset
APICheck is an HTTP API DevSecOps toolset, it integrates existing tools, creates execution chains easily and is designed for integration with 3rd parties.
trident - Automated Password Spraying Tool trident – Automated Password Spraying Tool
The Trident project is an automated password spraying tool developed to be deployed on multiple cloud providers and provides advanced options around scheduling
tko-subs - Detect & Takeover Subdomains With Dead DNS Records tko-subs – Detect & Takeover Subdomains With Dead DNS Records
tko-subs is a tool that helps you to detect & takeover subdomains with dead DNS records, this could be dangling CNAMEs point to hosting services and more.
Arcane - Tool To Backdoor iOS Packages (iPhone ARM) Arcane – Tool To Backdoor iOS Packages (iPhone ARM)
Arcane is a simple script tool to backdoor iOS packages (iPhone ARM) and create the necessary resources for APT repositories.
SharpHose - Asynchronous Password Spraying Tool SharpHose – Asynchronous Password Spraying Tool
SharpHose is an asynchronous password spraying tool in C# for Windows environments that takes into consideration fine-grained password policies and can be run over Cobalt Strike's execute-assembly.
Axiom - Pen-Testing Server For Collecting Bug Bounties Axiom – Pen-Testing Server For Collecting Bug Bounties
Project Axiom is a set of utilities for managing a small dynamic infrastructure setup for bug bounty, basically a pen-testing server out of the box with 1-line.


Comments are closed.