DiscussionTechnical

Apple Will Pay You $1 Million If You Can Hack This 🤯

Shawn Ryan Show

Apple offers a substantial bounty of $1 million for successfully exploiting a zero-click vulnerability in iPhones. The speaker shares insights into their bounty-hunting experience, mentioning large sums collected and the focus shifting away from this activity.

Summary

The conversation highlights Apple's incentive program that offers rewards for discovering vulnerabilities in their products, specifically mentioning a million-dollar bounty for a zero-click exploit that allows hackers to gain complete access to an iPhone without the user's knowledge. The speaker shares their experience in the field of cybersecurity, revealing that they have collected hundreds of bounties, although they no longer focus on this aspect of their work. They disclose their biggest bounty, valued at $128,000 in credits on a platform, while emphasizing their inability to discuss specific details due to non-disclosure agreements.

Key Insights

  • Apple offers a million-dollar bounty for exploiting a zero-click vulnerability that grants full access to iPhones without user awareness.
  • The speaker has collected bounties amounting to hundreds, indicating a significant level of experience in the cybersecurity field.
  • The largest bounty the speaker has collected was valued at $128,000 in credits, which they opted for over cash due to personal preference.
  • The speaker is bound by non-disclosure agreements, which prevent them from revealing the details of specific vulnerabilities or companies associated with their bounties.
  • Despite their extensive history in bounty hunting, the speaker indicates that this is not their current focus, suggesting a shift in their professional interests.

Topics

Apple Bounty ProgramZero-Click ExploitCybersecurity Experience

Transcript

[0:00] Apple, for example, if you were able to take over an iPhone, they'll pay you a million dollars for something like that. >> They'll pay you a million dollars? >> They call it a zero-click exploit, meaning I can send you something that you won't even know happened, and I have full access to your phone. Million-dollar bounty. >> What's the biggest bounty you've collected, and what was it for? >> I can't tell you what it was for. There's the disclosures, and there's non-disclosures. I can't disclose the company or what the vulnerability was, but it was $128,000 in credit on a platform. I chose that over the cash. [0:30] >> How many bounties have you collected? >>…

Full transcript available for MurmurCast members

Sign Up to Access

More from Shawn Ryan Show

Get AI summaries like this delivered to your inbox daily

Get AI summaries delivered to your inbox

MurmurCast summarizes your YouTube channels, podcasts, and newsletters into one daily email digest.