• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Analysts expected oil to surge above $200 but China has quietly kept prices half of that—and can’t for much longer

2

Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military

3

Marc Lore’s robots make 500 burrito bowls an hour. A human can make 45

1

Analysts expected oil to surge above $200 but China has quietly kept prices half of that—and can’t for much longer

2

Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military

3

Marc Lore’s robots make 500 burrito bowls an hour. A human can make 45
TechChanging Face of Security

Jailbreaks wanted: $1 million dollar iPhone hacks

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
September 21, 2015, 4:10 PM ET
New Year's Resolutions
Destroy your Smartphone! A New Year's Resolution. These devices can take control of your life.Photograph by Kevin Schafer — Getty Images

Ladies and gentlemen, start your engines.

The cybersecurity firm Zerodium announced on Monday that it will reward $1 million to anyone able to crack Apple’s (AAPL) recently launched iOS 9 operating system, which the startup’s website claims is “the world’s most secure mobile OS.”

“Apple iOS, like all operating system, is often affected by critical security vulnerabilities, however due to the increasing number of security improvements and the effectiveness of exploit mitigations in place, Apple’s iOS is currently the most secure mobile OS,” the company stated in its blog post. “But don’t be fooled, secure does not mean unbreakable, it just means that iOS has currently the highest cost and complexity of vulnerability exploitation and here’s where the Million Dollar iOS 9 Bug Bounty comes into play.”

Zerodium was founded this past summer by Chaouki Bekrar, a well-known merchant of zero-day exploits—or computer code that attacks previously unknown software vulnerabilities. His new startup said it is prepared to pay out a total of $3 million to as many as three hacking teams or individuals for successful attacks.

Apple, which is often lauded for its tight security, did not immediately respond to Fortune’s request for comment. (In an unrelated incident that was a rare lapse for the company, malware-laced apps recently made their way into the company’s app store in China.)

Bekrar also founded the controversial French cybersecurity firm Vupen, a brokerage built on the sale of computer bugs and exploits. Unlike Vupen, which handled all of its own research internally, Zerodium’s business is built on accepting submissions from external researchers. Both companies, however, rely on not disclosing their vulnerability findings to affected companies, such as Apple, Google (GOOG), or Microsoft (MSFT).

Instead, they sell them to the highest bidder, whether that be a law enforcement or spy agency, or another corporation.

When the so-called Stagefright vulnerability, which affected Google’s Android operating system, went public earlier this year, Bekrar said he would have paid the researcher who discovered the flaw $100,000 for it. (For more on Stagefright, read this.)

Christopher Soghoian, chief technologist at the American Civil Liberties Union, has referred to such businesses as “modern-day merchants of death,” since it can be difficult to keep track of where sold exploits end up and just as hard to prevent them from falling into the hands of oppressive regimes.

 

The zero-day trade industry is one which often operates out of the public spotlight, although a recent hacking of the Italian spyware firm Hacking Team helped expose some of its inner workings through leaked emails and other documents.

In order to claim the prize, which is the largest on record for an exploit of this sort, hackers must be able to demonstrate that they can remotely take control of the latest iOS devices such as the iPhone 6s or new iPads. For a full rundown of the rules and stipulations, see Zerodium’s website.

“For obvious security reasons, ZERODIUM does not maintain any web infrastructure dedicated to zero-day submissions. All submissions to ZERODIUM must be achieved through encrypted emails,” the website states (where one might expect a submission form). “We reserve the right, at our sole discretion, to make or to not make an offer to acquire a vulnerability for any/no reason.”

Whether the competition is a PR stunt for Bekrar’s new company or a legitimate contest, Fortune cannot say for certain.

Katie Moussouris, chief policy officer at the bug bounty startup HackerOne, told Fortune via email that such high prices for zero-day exploits could cause problems for tech companies attempting to secure their products. “These are not generally sustainable reward levels for defensive markets,” she wrote, “due to the difficulty in maintaining the necessary developer and tester employees who might just leave their day jobs if bounties like this are more common.”

Fittingly, submissions are due by Halloween: Oct. 31, 2015 at 6:00 P.M. (eastern standard time). Trick or treat, hackers.

Updated (Sept. 22, 2015): Below are comments provided to Fortune via email by Zerodium founder Chaouki Bekrar.

1. Why $ 1 million?

We believe that one million US dollars is high enough to motivate many talented researchers and entice them to accept this highly technical challenge.

2. Whom do you plan to sell the potential exploits to, if acquired? And
for how much money?

All acquired security research is made available to our customers which
include both government organizations and Fortune500 customers :-)

We cannot discuss financial information.

3. How much does Zerodium typically pay out for zero days? What are the most common types?

As of today, Zerodium has acquired various zero-day exploits mostly
affecting web browsers on Windows (Internet Explorer, Chrome, Firefox)
and Android. We’re currently spending between $400,000 to $600,000 per
month for vulnerability acquisitions, and we expect to spend around
$1,000,000 US dollars per month before the end of this year additionally
to the iOS bug bounty.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Dr. Shiv Rao speaks
Startups & VentureHealth
Abridge wants to be the operating system for medicine—and NVIDIA and Eli Lilly are helping build it
By Lily Mae LazarusJune 11, 2026
3 hours ago
Silicon Valley insiders warn U.S. defense supply chain is unprepared for modern warfare
AIBrainstorm Tech
Silicon Valley insiders warn U.S. defense supply chain is unprepared for modern warfare
By Sebastian HerreraJune 11, 2026
3 hours ago
Exclusive: Consumer device giant LG Electronics to launch blockchain to place and sell ads
CryptoBlockchain
Exclusive: Consumer device giant LG Electronics to launch blockchain to place and sell ads
By Jack Kubinec and Ben WeissJune 11, 2026
3 hours ago
As SpaceX goes public, a $100 billion shadow market faces a reckoning
Startups & VentureSpaceX
As SpaceX goes public, a $100 billion shadow market faces a reckoning
By Allie GarfinkleJune 11, 2026
4 hours ago
The real hurdle to enterprise AI isn’t fixing productivity KPIs. It’s ‘unlearning’ old habits, experts say
Future of WorkBrainstorm Tech
The real hurdle to enterprise AI isn’t fixing productivity KPIs. It’s ‘unlearning’ old habits, experts say
By Sebastian HerreraJune 11, 2026
4 hours ago
After backlash, Anthropic says its AI will now tell users when their request is being rejected or downgraded for national security concerns
AITech
After backlash, Anthropic says its AI will now tell users when their request is being rejected or downgraded for national security concerns
By Marco Quiroz-GutierrezJune 11, 2026
4 hours ago

Most Popular

Analysts expected oil to surge above $200 but China has quietly kept prices half of that—and can’t for much longer
Energy
Analysts expected oil to surge above $200 but China has quietly kept prices half of that—and can’t for much longer
By Sasha RogelbergJune 10, 2026
1 day ago
Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military
Asia
Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military
By Kate O'Keeffe and BloombergJune 8, 2026
3 days ago
Marc Lore’s robots make 500 burrito bowls an hour. A human can make 45
Innovation
Marc Lore’s robots make 500 burrito bowls an hour. A human can make 45
By Amanda GerutJune 9, 2026
2 days ago
Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there
Success
Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there
By Preston ForeJune 8, 2026
3 days ago
Corporate America has been draining the world's water. Matt Damon's new campaign calls on Gap, Starbucks, and Amazon to help give it back
Environment
Corporate America has been draining the world's water. Matt Damon's new campaign calls on Gap, Starbucks, and Amazon to help give it back
By Catherina GioinoJune 9, 2026
2 days ago
Current price of oil as of June 10, 2026
Personal Finance
Current price of oil as of June 10, 2026
By Joseph HostetlerJune 10, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.