Skip to main content

Google security researcher says Apple should pay $2.5M to charity for his iOS bug reports

A security researcher employed by Google has suggested that Apple should pay almost $2.5M to charity in return for reporting the iOS bugs he has discovered …

Ian Beer is a member of Google’s Project Zero team – which aims to identify security vulnerabilities in other company’s software and then give them 90 days to fix them before public disclosure. The initiative is aimed at making the whole Internet safer by effectively forcing companies to fix their bugs.

Apple has a bug bounty program, in which it pays security researchers for identifying bugs in its operating systems, but unlike almost every similar program, it’s invitation only. Business Insider reports that Beer worked out his reports would have accrued almost $1.23M in bounties had he been invited into the program. Allowing for Apple’s offer to double bounties when paid to charities, that would make them worth $2.45M.

It’s unclear if there was a specific reason Beer went public with his complaints about how Apple handles vulnerabilities and disclosures. He said in the notes alongside his talk that it was because Apple does a “poor job of fixing” the bugs he reports.

Apple launched its security bounty program two years ago, offering a maximum payout of $200k per vulnerability. A year later, however, the scheme was said to be faltering due to the relatively low payouts to researchers.

Researchers can earn much more selling the vulnerabilities to governments or firms involved in cracking Apple devices, with one startup earlier this year offering $3M for zero-day exploits in either iOS or macOS.


Check out 9to5Mac on YouTube for more Apple news:

FTC: We use income earning auto affiliate links. More.

You’re reading 9to5Mac — experts who break news about Apple and its surrounding ecosystem, day after day. Be sure to check out our homepage for all the latest news, and follow 9to5Mac on Twitter, Facebook, and LinkedIn to stay in the loop. Don’t know where to start? Check out our exclusive stories, reviews, how-tos, and subscribe to our YouTube channel

Comments

Author

Avatar for Ben Lovejoy Ben Lovejoy

Ben Lovejoy is a British technology writer and EU Editor for 9to5Mac. He’s known for his op-eds and diary pieces, exploring his experience of Apple products over time, for a more rounded review. He also writes fiction, with two technothriller novels, a couple of SF shorts and a rom-com!


Ben Lovejoy's favorite gear

Manage push notifications

notification icon
We would like to show you notifications for the latest news and updates.
notification icon
You are subscribed to notifications
notification icon
We would like to show you notifications for the latest news and updates.
notification icon
You are subscribed to notifications