vulns.co
/
GKData.io MCP

Apple · 2 min read

Apple Security Bounty

Apple · Independent. Policy reviewed 2026-10-03. Live terms govern participation.

Open current policy Reviewed policy

Policy and restrictions

Preserve confidentiality until Apple’s update and advisory; do not harm others’ data or availability. Apple Pay, non-public systems, third-party services, social engineering and unvalidated reports are excluded.

Eligibility and submission status

First complete actionable report through Apple’s portal; current-software/configuration requirements apply. Former employees, contractors and interns generally wait 18 months. Sanctions restrictions apply.

Official policy reviewed, but a live submission-acceptance indicator was not separately established.

Advertised rewards

Published base maximum $2,000,000; potential above $5,000,000 with applicable bonuses. Awards depend on demonstrated outcome, validation requirements and Apple’s discretion.

Advertised schedules and exceptional ceilings are not individual award evidence.

Published scope snapshot

Captured 2026-10-03. Check the current policy for changes before participating.

In scope · 8 published rows
AssetTypeGroup / eligibility
iOSoperating_systemCurrent public release, including eligible beta
iPadOSoperating_systemCurrent public release, including eligible beta
macOSoperating_systemCurrent public release, including eligible beta
tvOSoperating_systemCurrent public release, including eligible beta
visionOSoperating_systemCurrent public release, including eligible beta
watchOSoperating_systemCurrent public release, including eligible beta
Publicly available Apple hardwarehardware
Apple-owned public-facing web servers and servicespolicy_category
Out of scope · 3 published rows
AssetTypeGroup / eligibility
Apple Payproduct
Non-public-facing Apple systemspolicy_category
Third-party products and servicespolicy_category

Review limitations

  • Reviewed pages display dollar signs without an explicit ISO currency code; numeric currency-normalized bounds remain null.
  • Bonus-qualified ceilings are not guaranteed awards and must not be treated as ordinary base payouts.
  • No dedicated policy change-log URL was verified.
  • Only guidelines and terms were refreshed for scope context; reward and announcement evidence retains its earlier retrieval date. Scope summaries are non-exhaustive, omit asset inventories and testing instructions, and grant no authorization.

Sources and provenance

  1. Apple Security Bounty Apple · reviewed 2026-10-02
  2. Apple bounty categories Apple · reviewed 2026-10-02
  3. Apple bounty guidelines Apple · reviewed 2026-10-03
  4. Apple security terms and conditions Apple · reviewed 2026-10-03
  5. Apple Security Bounty evolved Apple · reviewed 2026-10-02
  6. Apple Security Bounty guidelines Apple · reviewed 2026-10-03
  7. Apple Security Bounty terms Apple · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software