Early access: this site has moved to bugrater.com.
AP

Self-hosted security programme

Apple

Apple does not use a third-party platform. Reports go directly to Apple Security Research and are triaged by Apple's own engineers. There is no profile to claim here, by design.

Reports are judged on demonstrated, reproducible impact. A primitive on its own is usually closed; show the whole chain on current, shipping software.

Direct How to report
In-house Triage
$5k–$2M Published range
Release notes Where credit lands

Featured write-up

Authentication Bypass on *.apple.com

“Hunting on Apple requires patience, but verifying a successful fix makes the wait worthwhile. I reported a vulnerability on *.apple.com where a advance client-side response manipulation allowed a complete bypass of the authentication gate. Tracking the status took some proactive follow-up. While their initial response times can feel slug…”

RA Rathore · 1 reports
Read the write-up ★★★★☆ · August 2026

Getting credit

Report to Apple, claim it here

Credit publishes in Apple’s own advisories, often months after the report. We index those, so it is waiting for you, including recognitions that carry no CVE and appear nowhere else.

NR Unrated
Apple
Apple HackerOne
3 more reviews needed for a grade

Found a vulnerability?

Apple runs its own vulnerability reporting process. Here are your two ways to report it. We recommend the first.

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Program metrics HackerOne · published

HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 24 Sep 2026.

What it pays, by severity

Critical no reports on record
High no reports on record
Medium no reports on record
Low no reports on record

Intake & responsiveness · last 90 days

Reports received
not published
in 90 days
Resolved
not published
all time
Participants
0
hunters engaged
Response efficiency
not published
HackerOne’s figure
SLA misses
0
targets missed

Getting in the door

Open to submit. Nothing HackerOne publishes stands between a hunter and a first report here.

Over 35 days (19 snapshots): no change on the figures worth watching.

Reviews

0 published

No reviews yet.

Be the first to review

Program profile HackerOne · imported

Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 20 Sep 2026.

Think different