logoalt Hacker News

muglug • today at 3:56 PM • 2 replies • view on HN

As I understand it, bug bounty awards are a rough proxy for "would nation-state actors be able to exploit this for operational purposes without getting caught".

Zero-click iPhone exploits that affect the current OS and also previous ones are worth hundreds of thousands.


Replies

yieldcrv • today at 5:28 PM

thats the true market value of bug bounty awards

the unilaterally set awards by the affected corporation are far lower and based on the price of the researcher’s liability

buckle8017 • today at 4:20 PM

Try 10-20 million USD for a zero click iPhone exploit.