Big bugs
Significant rewards have been paid in bug bounty programs as a form of recognition to security researchers for discovering significant vulnerabilities. Some of the largest bounties known to date include the following:
- $1.5 million – Zerodium: Zerodium is a company known for buying and selling zero-day exploits and vulnerabilities. In certain cases, they have offered significant bounties, such as paying $1.5 million for a zero-day exploit in iOS. These zero-day exploits are unknown vulnerabilities that can be used to compromise systems before the vulnerability is known and fixed.
- $1 million – Apple: Apple established its security bounty program in 2016 to reward researchers who find and report critical vulnerabilities in its systems. While specific details about the vulnerabilities for which rewards of up to $1 million were paid are not known, the company is known to have offered significant rewards for identifying critical security issues in its devices...