Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Apple did not cut its entire security-bounty program. In November 2025 it reduced several rewards for standalone macOS findings, including some Transparency, Consent, and Control (TCC) bypasses and Mac-only sandbox escapes, while raising the ceiling for sophisticated, multi-stage attacks to $2 million—and potentially more than $5 million with bonuses. The change matters because Mac malware observed in 2025 became more focused on credential theft, even though that trend does not prove the bounty cuts caused more infections.
What changed in Apple’s bounty program?
The controversy began with a December 2, 2025 report from 9to5Mac, citing macOS researcher Csaba Fitzl. Fitzl compared earlier figures with Apple’s revised categories and argued that several Mac-specific rewards had fallen sharply. Apple’s own current schedule confirms lower payouts for some standalone outcomes, but it also shows a much more generous top tier for complete exploit chains.
| Finding | Previously reported figure | Current published macOS figure | What the figure depends on |
|---|---|---|---|
| Full TCC bypass | $30,500 | $5,000 in the cited unsandboxed-app category | Exploit path, app sandbox status, Target Flag use and demonstrated access |
| Individual TCC category | $5,000–$10,000 | $1,000 without the TCC Target Flag | A Target Flag demonstration can qualify for $5,000 or $10,000 depending on sandbox status |
| macOS sandbox escape | $10,000 | $5,000 | Apple describes this as a macOS-only escape |
| Complete Gatekeeper bypass | Not the focus of the reported cuts | Up to $100,000 | Requires Apple’s specified quarantine, download and opening scenario |
These are not automatic prices for bug labels. Apple evaluates the affected version, prerequisites, reproducibility, exploit quality and real-world impact. Its published categories also distinguish a TCC Target Flag capture from access to sensitive data without that flag.
The rewards that increased
Apple’s October 10, 2025 redesign raised maximums for attacks it considers strategically dangerous:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- Remote attack without user interaction: up to $2 million, versus $1 million previously.
- Remote attack requiring one click: up to $1 million, versus $250,000.
- Wireless-proximity attack: up to $1 million, versus $250,000.
- Physical access to a device: up to $500,000, versus $250,000.
- App Sandbox escape reaching an SPTM bypass: up to $500,000, versus $150,000.
- WebKit WebContent sandbox escape: up to $300,000.
- Complete Gatekeeper bypass: up to $100,000.
Apple says its public program, launched in 2020, had paid more than $35 million to over 800 researchers. The redesigned structure took effect in November 2025 and added Target Flags intended to make exploitability easier to verify. Apple describes the change in its program announcement as an outcome-based model: the complete, demonstrable attack receives the largest reward, while individual components remain eligible for smaller payments.
Why TCC and sandbox escapes matter
TCC protects sensitive data
Transparency, Consent, and Control is macOS’s permission framework. It governs access to information and capabilities such as files, Contacts, Calendars, Photos, microphones, cameras and screen recording. A TCC bypass can let an application reach protected information without the permission a user normally expects to grant.
The impact is not automatically total control of a Mac. One flaw might expose a single data category; another could provide broader access. Apple’s current categories therefore separate limited data access from a demonstrated modification of the relevant TCC database.
The App Sandbox limits applications
App Sandbox restricts what an application can read, change and launch. A sandbox escape lets code running in that restricted environment reach resources outside its assigned limits. A Mac-only escape is a serious boundary failure, but it is not the same payout category as a chain that proceeds to a more privileged platform compromise.
Recommended Free Tools
Apple’s rationale—and the unresolved incentive problem
Apple says stronger defenses have made advanced exploit development more difficult and time-consuming, and that rewards should reflect verified, practical outcomes. Its highest payments are aimed at chains resembling sophisticated mercenary-spyware attacks: for example, a remote entry point combined with a browser or sandbox escape and a final privilege or data-access step. Apple also says incomplete chains and individual components remain eligible, but at proportionally smaller amounts.
That logic is coherent if the goal is to attract research into the attacks Apple considers most dangerous. The objection is economic. A researcher may spend months finding and validating a Mac privacy-boundary bug yet receive only a few thousand dollars if the flaw cannot be connected to a larger chain. Fitzl argued that Apple’s approach undervalues Mac security and could make alternative markets look more attractive. That is a plausible incentive concern, not evidence that researchers are definitively selling bugs to criminal or spyware buyers.
Rank #3
The key policy question is whether an isolated TCC bypass should be valued only by its role in a complete exploit chain. Such a bug may be especially useful to malware that has already persuaded a user to run a trojanized application. A lower bounty could therefore reduce the supply of responsibly reported fixes even while Apple spends more to discover rare, high-end chains.
What the malware data actually shows
Jamf’s 2026 Mac report, using 2025 data from more than 150,000 Mac devices, found that trojans represented 50.32% of observed malware and infostealers 33.52%. Jamf also reported a 28.08% increase in the share of studied malware represented by infostealers in its prior comparison. Those percentages describe Jamf’s telemetry and research samples, not the infection rate for every Mac worldwide; the annual datasets and methods differ.
The trend is still important. Infostealers seek passwords, browser credentials, cookies, cryptocurrency wallets and other valuable data. Trojans abuse user trust by posing as legitimate applications, updates or utilities. Jamf says newer infostealers increasingly add trojan backdoors and persistence instead of stealing data and disappearing.
Rank #4
Many of these campaigns rely on fake installers, malicious advertising, social engineering or user-approved execution rather than a remotely exploitable macOS zero-day. Consequently, rising observed malware does not prove that Apple’s bounty reductions caused more infections, and it does not demonstrate that macOS security boundaries have failed.
Does the program remain attractive?
More attractive work
- Complete exploit chains with a clear real-world outcome.
- Remote, zero-click, browser, wireless or cross-device attacks.
- Research against current hardware and software that meets Apple’s latest-version rule.
- Reports that demonstrate the relevant Target Flags and can be verified quickly.
Less attractive work
- Isolated Mac privacy-boundary flaws.
- A bug exposing one TCC category without a Target Flag or broader chain.
- Mac-only findings that cannot be combined with another vulnerability.
- Research whose commercial opportunity is measured against exploit markets rather than Apple’s legal bounty.
Apple’s guidelines generally require a first, actionable report affecting the latest public operating system or applicable beta, a reliable reproduction or working exploit, and a credible security or privacy impact. Reports must remain undisclosed until Apple issues an update and advisory. The terms state that submission does not guarantee payment; theoretical claims, incomplete reports, unvalidated AI-generated claims and third-party vulnerabilities are not eligible.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What Target Flags do
Target Flags are verification markers for exploitability. Apple’s examples include a Commpage flag demonstrating register control, arbitrary read/write or code execution, and a TCC flag demonstrating modification of the relevant user or system TCC database. Apple’s researcher documentation shows tccutil flag check for checking whether the relevant TCC database was modified. This is a bounty-validation mechanism, not a consumer malware-removal command. Details are documented at Apple’s Target Flags page.
Best Value
What Mac users and administrators should do
The bounty dispute does not create an immediate consumer emergency, but it is a reminder not to treat Macs as malware-proof.
- Install macOS and application updates promptly, including security responses.
- Avoid pirated, cracked or unexpectedly repackaged software and verify downloads through trusted channels.
- Treat unsolicited password prompts, fake update dialogs and requests for broad privacy permissions as suspicious.
- Use separate standard accounts where practical, strong account protection and reliable offline or versioned backups.
- In organizations, combine least privilege with application control, centralized patching, endpoint detection and response, and monitoring for credential theft.
- Do not assume notarization or code signing alone proves an application is safe; trusted distribution paths can still be abused.
Apple’s built-in controls—including Gatekeeper, XProtect, notarization, TCC, FileVault, software updates and Lockdown Mode—remain the baseline. Fleet administrators can review Apple’s Platform Security guide when deciding which controls need additional management or telemetry.
The bottom line
Apple’s November 2025 redesign is best understood as a reprioritization, not a universal bounty cut. The company reduced several middle-tier rewards for standalone macOS TCC and sandbox findings while dramatically increasing payouts for complete, high-impact exploit chains. At the same time, Jamf observed a Mac-malware mix increasingly dominated by trojans and infostealers. The unresolved issue is whether Apple’s emphasis on spectacular chains leaves privacy-impacting Mac bugs economically undervalued—the kind of bugs that can help ordinary malware succeed even when they never become a million-dollar zero-click exploit.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




