Because that XSS wasn’t actually critical, the CVSS string was also incorrect because it was filled out by the researcher and wasn’t actually assessed by NVD.
dvfjsdhgfv•3mo ago
Even if you get the maximum amount, that is still less than the NSO (recently acquired by "Investors") would offer for a zero-day.
general1465•3mo ago
https://9to5mac.com/2025/07/31/apple-security-bounties-pay-u...
dogma1138•3mo ago