Remix.run Logo
▲ muglug 3 hours ago

As I understand it, bug bounty awards are a rough proxy for "would nation-state actors be able to exploit this for operational purposes without getting caught".

Zero-click iPhone exploits that affect the current OS and also previous ones are worth hundreds of thousands.

▲buckle8017 3 hours ago | parent | next [-]

Try 10-20 million USD for a zero click iPhone exploit.

▲yieldcrv 2 hours ago | parent | prev [-]

thats the true market value of bug bounty awards

the unilaterally set awards by the affected corporation are far lower and based on the price of the researcher’s liability