Early access: the directory is still filling out, and every rating here is a reported experience.
AP

Self-hosted security programme

Apple

Apple does not use a third-party platform. Reports go directly to Apple Security Research and are triaged by Apple's own engineers. There is no profile to claim here, by design.

Reports are judged on demonstrated, reproducible impact. A primitive on its own is usually closed; show the whole chain on current, shipping software.

Direct How to report
In-house Triage
$5k–$2M Published range
Release notes Where credit lands

Featured write-up

Authentication Bypass on *.apple.com

“Hunting on Apple requires patience, but verifying a successful fix makes the wait worthwhile. I reported a vulnerability on *.apple.com where a advance client-side response manipulation allowed a complete bypass of the authentication gate. Tracking the status took some proactive follow-up. While their initial response times can feel slug…”

RA Rathore · 1 reports
Read the write-up ★★★★☆ · August 2026

Getting credit

Report to Apple, claim it here

Credit publishes in Apple’s own advisories, often months after the report. We index those, so it is waiting for you, including recognitions that carry no CVE and appear nowhere else.

NR Unrated
Apple Security Bounty
Apple Independent · self-hosted $5,000–$2,000,000
1 more review needed for a grade
Reported practices
+ Assigns CVEs 2 reports
+ Credits researchers 2 reports
+ Clear, honest scope 2 reports
+ Responsive communication 1 report
+ Consistent decisions 1 report
+ Respectful & professional 1 report
+ Clear, current policy 1 report
+ Engages on the technical detail 1 report
Slow to pay 2 reports
Slow to first response 1 report

Found a vulnerability?

Apple runs its own vulnerability reporting process. Here are your two ways to report it. We recommend the first.

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Reviews

2 published
Authentication Bypass on *.apple.com
positive

Hunting on Apple requires patience, but verifying a successful fix makes the wait worthwhile. I reported a vulnerability on *.apple.com where a advance client-side response manipulation allowed a complete bypass of the authentication gate. Tracking the status took some proactive follow-up. While their initial response times can feel sluggish compared to standard bug bounty platforms, the Apple Security Team was professional once communication opened up regarding the remediation and potential bounty rewards. The highlight was working through the remediation phase and actively verifying the fix once they patched the flaw. For other researchers targeting Apple: rely heavily on manual testing and business logic over automated scanners, document your reproduction steps flawlessly, and don't be afraid to politely ping them for updates while you wait.

reports 1 1st reply 1–3 months resubmit yes recommends yes skill Intermediate
+ Assigns CVEs + Clear, current policy + Clear, honest scope + Credits researchers − Slow to pay − Slow to first response
Rathore · Aug 8, 2026 · Share ↗ 2 helpful
0 comments

Log in to comment

Responsive, fair, and quick.
positive

I have spent the last 4 months interacting with the Apple security response team (SRT). They have been incredibly thorough with their evaluations, informative closes are almost always accompanied by a detailed explanation as to why it is not applicable. They are fast with triage and will usually move on your report within 48 hours. The surface however, is increasingly hardened as automated security research has massively accelerated the speed at which it used to take. As such, the most critical note when submitting to Apple, always, and I mean always, prove the impact, weaponize the exploit, demonstrate the chain. If any part reads as theoretical, it will not strengthen the case for the report.

via Direct / email reports 9 paid $500 – $2k 1st reply Within 3 days resubmit yes recommends yes skill Advanced
+ Assigns CVEs + Clear, honest scope + Consistent decisions + Credits researchers + Engages on the technical detail + Respectful & professional + Responsive communication − Slow to pay
Month Sev Outcome Why closed Bounty
Apr 2026 High Resolved not set $500 – $2k
Maliq Barnard ✓ verified · Aug 3, 2026 · Share ↗ 2 helpful
0 comments

Log in to comment