October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Apple Cut Some Mac Security Bounties as Malware Shifts Toward Trojans and Infostealers

Apple reduced several macOS-specific bounty categories in November 2025 but raised rewards for sophisticated exploit chains. The shift comes as Jamf reports trojans and infostealers dominated observed Mac malware in 2025.
From TheFinanceBase Team6 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Apple did not cut its entire security-bounty program. In November 2025 it reduced several rewards for standalone macOS findings, including some Transparency, Consent, and Control (TCC) bypasses and Mac-only sandbox escapes, while raising the ceiling for sophisticated, multi-stage attacks to $2 million—and potentially more than $5 million with bonuses. The change matters because Mac malware observed in 2025 became more focused on credential theft, even though that trend does not prove the bounty cuts caused more infections.

What changed in Apple’s bounty program?

The controversy began with a December 2, 2025 report from 9to5Mac, citing macOS researcher Csaba Fitzl. Fitzl compared earlier figures with Apple’s revised categories and argued that several Mac-specific rewards had fallen sharply. Apple’s own current schedule confirms lower payouts for some standalone outcomes, but it also shows a much more generous top tier for complete exploit chains.

Finding Previously reported figure Current published macOS figure What the figure depends on
Full TCC bypass $30,500 $5,000 in the cited unsandboxed-app category Exploit path, app sandbox status, Target Flag use and demonstrated access
Individual TCC category $5,000–$10,000 $1,000 without the TCC Target Flag A Target Flag demonstration can qualify for $5,000 or $10,000 depending on sandbox status
macOS sandbox escape $10,000 $5,000 Apple describes this as a macOS-only escape
Complete Gatekeeper bypass Not the focus of the reported cuts Up to $100,000 Requires Apple’s specified quarantine, download and opening scenario

These are not automatic prices for bug labels. Apple evaluates the affected version, prerequisites, reproducibility, exploit quality and real-world impact. Its published categories also distinguish a TCC Target Flag capture from access to sensitive data without that flag.

The rewards that increased

Apple’s October 10, 2025 redesign raised maximums for attacks it considers strategically dangerous:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Remote attack without user interaction: up to $2 million, versus $1 million previously.
  • Remote attack requiring one click: up to $1 million, versus $250,000.
  • Wireless-proximity attack: up to $1 million, versus $250,000.
  • Physical access to a device: up to $500,000, versus $250,000.
  • App Sandbox escape reaching an SPTM bypass: up to $500,000, versus $150,000.
  • WebKit WebContent sandbox escape: up to $300,000.
  • Complete Gatekeeper bypass: up to $100,000.

Apple says its public program, launched in 2020, had paid more than $35 million to over 800 researchers. The redesigned structure took effect in November 2025 and added Target Flags intended to make exploitability easier to verify. Apple describes the change in its program announcement as an outcome-based model: the complete, demonstrable attack receives the largest reward, while individual components remain eligible for smaller payments.

Why TCC and sandbox escapes matter

TCC protects sensitive data

Transparency, Consent, and Control is macOS’s permission framework. It governs access to information and capabilities such as files, Contacts, Calendars, Photos, microphones, cameras and screen recording. A TCC bypass can let an application reach protected information without the permission a user normally expects to grant.

The impact is not automatically total control of a Mac. One flaw might expose a single data category; another could provide broader access. Apple’s current categories therefore separate limited data access from a demonstrated modification of the relevant TCC database.

The App Sandbox limits applications

App Sandbox restricts what an application can read, change and launch. A sandbox escape lets code running in that restricted environment reach resources outside its assigned limits. A Mac-only escape is a serious boundary failure, but it is not the same payout category as a chain that proceeds to a more privileged platform compromise.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Apple’s rationale—and the unresolved incentive problem

Apple says stronger defenses have made advanced exploit development more difficult and time-consuming, and that rewards should reflect verified, practical outcomes. Its highest payments are aimed at chains resembling sophisticated mercenary-spyware attacks: for example, a remote entry point combined with a browser or sandbox escape and a final privilege or data-access step. Apple also says incomplete chains and individual components remain eligible, but at proportionally smaller amounts.

That logic is coherent if the goal is to attract research into the attacks Apple considers most dangerous. The objection is economic. A researcher may spend months finding and validating a Mac privacy-boundary bug yet receive only a few thousand dollars if the flaw cannot be connected to a larger chain. Fitzl argued that Apple’s approach undervalues Mac security and could make alternative markets look more attractive. That is a plausible incentive concern, not evidence that researchers are definitively selling bugs to criminal or spyware buyers.

The key policy question is whether an isolated TCC bypass should be valued only by its role in a complete exploit chain. Such a bug may be especially useful to malware that has already persuaded a user to run a trojanized application. A lower bounty could therefore reduce the supply of responsibly reported fixes even while Apple spends more to discover rare, high-end chains.

What the malware data actually shows

Jamf’s 2026 Mac report, using 2025 data from more than 150,000 Mac devices, found that trojans represented 50.32% of observed malware and infostealers 33.52%. Jamf also reported a 28.08% increase in the share of studied malware represented by infostealers in its prior comparison. Those percentages describe Jamf’s telemetry and research samples, not the infection rate for every Mac worldwide; the annual datasets and methods differ.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The trend is still important. Infostealers seek passwords, browser credentials, cookies, cryptocurrency wallets and other valuable data. Trojans abuse user trust by posing as legitimate applications, updates or utilities. Jamf says newer infostealers increasingly add trojan backdoors and persistence instead of stealing data and disappearing.

Many of these campaigns rely on fake installers, malicious advertising, social engineering or user-approved execution rather than a remotely exploitable macOS zero-day. Consequently, rising observed malware does not prove that Apple’s bounty reductions caused more infections, and it does not demonstrate that macOS security boundaries have failed.

Does the program remain attractive?

More attractive work

  • Complete exploit chains with a clear real-world outcome.
  • Remote, zero-click, browser, wireless or cross-device attacks.
  • Research against current hardware and software that meets Apple’s latest-version rule.
  • Reports that demonstrate the relevant Target Flags and can be verified quickly.

Less attractive work

  • Isolated Mac privacy-boundary flaws.
  • A bug exposing one TCC category without a Target Flag or broader chain.
  • Mac-only findings that cannot be combined with another vulnerability.
  • Research whose commercial opportunity is measured against exploit markets rather than Apple’s legal bounty.

Apple’s guidelines generally require a first, actionable report affecting the latest public operating system or applicable beta, a reliable reproduction or working exploit, and a credible security or privacy impact. Reports must remain undisclosed until Apple issues an update and advisory. The terms state that submission does not guarantee payment; theoretical claims, incomplete reports, unvalidated AI-generated claims and third-party vulnerabilities are not eligible.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What Target Flags do

Target Flags are verification markers for exploitability. Apple’s examples include a Commpage flag demonstrating register control, arbitrary read/write or code execution, and a TCC flag demonstrating modification of the relevant user or system TCC database. Apple’s researcher documentation shows tccutil flag check for checking whether the relevant TCC database was modified. This is a bounty-validation mechanism, not a consumer malware-removal command. Details are documented at Apple’s Target Flags page.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What Mac users and administrators should do

The bounty dispute does not create an immediate consumer emergency, but it is a reminder not to treat Macs as malware-proof.

  • Install macOS and application updates promptly, including security responses.
  • Avoid pirated, cracked or unexpectedly repackaged software and verify downloads through trusted channels.
  • Treat unsolicited password prompts, fake update dialogs and requests for broad privacy permissions as suspicious.
  • Use separate standard accounts where practical, strong account protection and reliable offline or versioned backups.
  • In organizations, combine least privilege with application control, centralized patching, endpoint detection and response, and monitoring for credential theft.
  • Do not assume notarization or code signing alone proves an application is safe; trusted distribution paths can still be abused.

Apple’s built-in controls—including Gatekeeper, XProtect, notarization, TCC, FileVault, software updates and Lockdown Mode—remain the baseline. Fleet administrators can review Apple’s Platform Security guide when deciding which controls need additional management or telemetry.

The bottom line

Apple’s November 2025 redesign is best understood as a reprioritization, not a universal bounty cut. The company reduced several middle-tier rewards for standalone macOS TCC and sandbox findings while dramatically increasing payouts for complete, high-impact exploit chains. At the same time, Jamf observed a Mac-malware mix increasingly dominated by trojans and infostealers. The unresolved issue is whether Apple’s emphasis on spectacular chains leaves privacy-impacting Mac bugs economically undervalued—the kind of bugs that can help ordinary malware succeed even when they never become a million-dollar zero-click exploit.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.