HeadlinesBriefing favicon HeadlinesBriefing.com

Apple's Bug Bounty Changes Explained

9to5Mac •
×

Apple's recent security vulnerability patches in macOS, iOS, and iPadOS have included a significant number of credits for AI tools like Claude and Codex. This surge in AI-generated findings prompted Apple to cap the number of open vulnerability reports per researcher and implement a 30-day cool-off period. Initially, these changes seemed like a defensive reaction, but a closer look reveals they are part of a strategy initiated in October 2025.

Apple's "major evolution" of its security bug bounty program then introduced a $2 million top prize and the "Target Flags" system, allowing for programmatic validation of exploits. This enabled faster payouts and, crucially, a way to differentiate between AI-discoverable bugs and those requiring human expertise. Further baffling changes in December 2025 saw reduced payouts for common vulnerabilities like TCC bypasses and sandbox escapes, while increasing rewards for complex exploit chains.

When viewed together, these moves appear to be a coordinated response to the influx of AI-generated reports. By devaluing shallower, AI-identifiable bugs and prioritizing more sophisticated exploits that still demand human ingenuity, Apple is adapting its bug bounty program to the realities of AI-assisted security research. This marks the beginning of the program's "AI growing pains."