• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Techbug bounties

Apple Has a Million Dollar Bug Problem—And It’s Only Paying Thousands to Squash Them

By
Xavier Harding
Xavier Harding
Down Arrow Button Icon
By
Xavier Harding
Xavier Harding
Down Arrow Button Icon
July 31, 2019, 6:00 AM ET

Details of six new vulnerabilities in Apple’s iOS mobile operating system were made available on Tuesday. Discovered by researchers with Google, several of the security flaws were particularly worrisome because they could potentially let hackers compromise iPhones without making owners aware. Many of the bugs were disclosed months ago, and all but one has already been patched.

While the disclosure of these bugs made for eye-popping headlines, they also betray a deeper issue within Apple’s ecosystem. Specifically, iPhone flaws that require no interaction on the behalf of users, like the ones the Google researchers discovered, would garner large sums if sold on the black market. Apple, meanwhile, pays much less. Is that pay gap a problem?

Natalie Silvanovich and Samuel Groß, two members of Google’s research team dubbed Project Zero, were credited with finding the iOS bugs. Silvanovich tells ZDNet that four out of the six security flaws can be executed automatically simply by sending an iPhone user a specific string of characters on iMessage, and then having the user open the message and view the contents within. The other two iOS bugs let hackers leak data from the iPhone’s memory and read files from a remote device.

While Apple addressed all six of the iOS flaws with the July 22 release of iOS 12.4, one of the vulnerabilities has yet to be fully resolved.

Should Apple pay more for bugs?

According to a Google spokesperson, the company did not receive an award for finding these vulnerabilities. Apple did not respond to Fortune’s requests for comment. Apple has said it pays those who find vulnerabilities up to $200,000 through a program it started in 2016. (A week after Apple launched this bug bounty, a third-party launched its own, doubling the prize money offered by Cupertino.) In comparison, exploit acquisition platform Zerodium rewards security researchers as much as $2 million for bugs similar to what Google has disclosed.

Apple has kept quiet about how much money it has paid out in bug bounties. For example, when it rewarded 14-year-old Grant Thompson for discovering Apple’s FaceTime eavesdropping bug, it said it would pay the Thompson family for the discovery, as well as provide money for Grant’s education, but it didn’t disclose how much it ultimately paid. In other cases, bug finders have kept Apple’s software flaws to themselves because the company is stingy about paying out. The policy has been clearly been a thorn in the side of Apple, a trillion-dollar company.

Or has it? Economics are behind the reason Apple’s payouts aren’t high, says Katie Moussouris, founder and CEO of Luta Security. Moussouris founded Microsoft’s Security Vulnerability Research program in 2013. In advance of launching Microsoft’s first bug bounty program, she studied business, game theory, and other bounty programs to arrive at a proper payout price.

“Mozilla was one of the first companies to offer a bug bounty program, offering finders $500.” Moussouris says, “Google itself only started offering money in 2010, with a bounty of $1,337.”

But now that bounties have swollen into six figures, it’s more important than ever for companies like Apple to keep its employees happy. Moussouris notes that workers within the company find similar bugs multiple times each year, but don’t see such large payouts.

“There have been times where an Apple researcher has gone to their manager saying, ‘I found four bugs that you’d pay an outsider $200,000 for each. Can I at least get a bonus?'” says Moussouris. “The response, unfortunately, has been, ‘That’s what we pay you a salary for.'”

Moussouris says she ran into a similar problem at Microsoft when she devised a bug bounty prize of $100,000—matching the popular Pwn2Own hacker contest bounty at the time.

By paying too much to bug bounty hunters, companies can cannibalize their hiring, she says. “You won’t be able to get new recruits to come work for you full time and prevent bugs in the first place, when they could potentially earn an entire salary from winning a single bug bounty on their own.”

So, while Apple may be one of the richest companies in the world, the computer maker’s decision to cap its bounty at $200,000 could be seen as a sustainable one. And while the black market will always find a way to outbid Apple’s rewards, the iPhone-maker can devote its war chest toward keeping its security strong to begin with.

Update, July 31 1:15 p.m.: This story was updated from its original version to include a comment from Google.

More must-read stories from Fortune:

—How the government should spend Facebook’s $5 billion fine

—Cloud gaming is big tech’s new street fight

—Should companies bolster their cybersecurity by “hacking back”?

—FaceApp’s Russia link is the latest alarm in an ongoing digital red scare

—Equifax may owe you some money. Here’s how to get it

Catch up with Data Sheet, Fortune‘s daily digest on the business of tech.

About the Author
By Xavier Harding
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
Fortune Secondary Logo
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

PoliticsColleges and Universities
Pentagon chief blocks officers from attending Ivy League schools and other top universities, including partners on AI and space
By Jason MaFebruary 28, 2026
4 hours ago
AIAnthropic
Anthropic CEO Dario Amodei says ‘we are patriotic Americans’ committed to defending the U.S. but won’t budge on ‘red lines’
By Jason MaFebruary 28, 2026
9 hours ago
sarandos
InvestingMedia
3 things we will never know after Netflix pulled out of the Warner Bros. bidding, handing it to Paramount
By Nick LichtenbergFebruary 28, 2026
12 hours ago
OpenAI CEO Sam Altman
AIAnthropic
OpenAI sweeps in to ink deal with Pentagon as Anthropic is designated a ‘supply chain risk’—an unprecedented action likely to crimp its growth
By Jeremy KahnFebruary 28, 2026
12 hours ago
Big TechAmerican Politics
Your spend as a ‘weapon’: Scott Galloway’s ‘Resist and Unsubscribe’ movement asks you to ditch Amazon, Apple, and Netflix to oppose Trump
By Kristin StollerFebruary 28, 2026
16 hours ago
world's fair
CommentaryRobots
Something big is happening in AI, but panic is the wrong reaction
By Peter CappelliFebruary 28, 2026
17 hours ago

Most Popular

placeholder alt text
Success
Japanese companies are paying older workers to sit by a window and do nothing—while Western CEOs demand super-AI productivity just to keep your job
By Orianna Rosa RoyleFebruary 27, 2026
2 days ago
placeholder alt text
Middle East
Iran is now on 'death ground' amid existential threat from U.S. attacks and could 'go big' in retaliation, former NATO commander warns
By Jason MaFebruary 28, 2026
10 hours ago
placeholder alt text
AI
The week the AI scare turned real and America realized maybe it isn't ready for what's coming
By Nick LichtenbergFebruary 28, 2026
17 hours ago
placeholder alt text
Success
Walmart exec says U.S. workforces needs to take inspiration from China where ‘5 year-olds are learning DeepSeek’
By Preston ForeFebruary 27, 2026
2 days ago
placeholder alt text
Personal Finance
Current price of gold as of February 27, 2026
By Danny BakstFebruary 27, 2026
2 days ago
placeholder alt text
Law
China's government intervenes to show Michigan scientists were carrying worms, not biological materials
By Ed White and The Associated PressFebruary 26, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.