An Apple security chief unexpectedly announced the company will pay for vulnerabilities found in certain aspects of iOS and iCloud. The program will launch in September by invitation only for a few dozen researchers with whom Apple has an existing strong relationship, and payouts will be based on severity and category. The top fees across five areas range from $25,000 to $200,000, but could be much lower. The announcement came during a presentation by Ivan Krstic, Apple’s head of security engineering and architecture, at the Black Hat security research conference in Las Vegas.
The presentation also included a level of technical detail and disclosure of security – here, related to AutoUnlock, HomeKit, and iCloud Keychain – that has been mostly absent in the past at conferences, according to those present.…