Just weeks after Apple hiked the rewards under its Security Bounty program to a new zenith , the tech giant has now drastically slashed its monetary awards for finding macOS-related security vulnerabilities, and that too at a time when Mac-related malware attacks are becoming increasingly prevalent.
Csaba Fitzl, a macOS security researcher at Iru, has now penned an interesting LinkedIn post, .
As is evident from Fitzl's post reproduced in the above snippet, Apple has drastically curtailed monetary awards under several macOS-geared categories:
- The rewards for full Transparency, Consent, and Control (TCC) bypasses - vulnerabilities that allow malicious apps to access sensitive personal data without explicit user authorization - have now been slashed by 83 percent to just $5,000 vs. the previous award of $30,500.
- macOS sandbox escapes are down by 50 percent to $5,000 from the previous award level of around $10,000.
- The reward for a vulnerability that manages to obtain sensitive data protected by TCC, such as Photos, but does not use the TCC Target Flag, is now eligible for a $1,000 reward.
You can verify these figures by going to :
Of course, over the years, the bounty program has , which now includes:
- A dedicated Lockdown Mode - attack vectors are minimized by blocking attachments, link previews, web-based restrictions, among other steps.
- An upgraded security architecture of the Safari browser.
- Memory Integrity Enforcement - a security feature in chips such as the A19 which protects against memory corruption vulnerabilities.
Nonetheless, by arbitrarily curtailing the bounty for finding vulnerabilities in the macOS, Apple has taken an apparent regressive step, one that would render the popular OS more vulnerable to security exploits. It seems Apple no longer loves Macs.
Follow to get more of our news coverage in your feeds.