Google has significantly revamped its Android and Chrome vulnerability rewards programs, introducing substantially higher bounties for the most complex security discoveries while adjusting rewards for vulnerabilities that artificial intelligence (AI) has simplified to identify.
The technology giant now offers rewards of up to $1.5 million for the most sophisticated Android exploits – specifically zero-click attacks targeting the Pixel Titan M2 security chip that achieve full-chain compromise with persistence capabilities. For similar exploits without persistence mechanisms, researchers can still earn up to $750,000.
In the Chrome vulnerability program, full-chain browser process exploits targeting up-to-date systems and hardware now qualify for rewards reaching $250,000, with an additional $250,128 bonus available for successfully exploiting MiraclePtr-protected memory allocations.
Google has shifted its focus toward concise security reports containing only essential bug proofs and technical artifacts, moving away from lengthy written analyses that AI systems can now generate automatically. This approach ensures researchers concentrate on genuine discovery rather than documentation that could be automated.
For Android-specific submissions, the program prioritizes Linux kernel vulnerabilities within Google-maintained components, unless researchers can provide concrete evidence of exploitability on actual Android devices.
These program enhancements follow a record-breaking year for Google’s bug bounty initiatives, with the company distributing $17.1 million to 747 security researchers in 2025 – representing a 40% increase from 2024 and establishing a new all-time high. Since the vulnerability rewards program launched in 2010, cumulative payouts have exceeded $81.6 million.
Google anticipates that total aggregate rewards for 2026 will continue growing despite reductions in certain individual bounty amounts, reflecting the increasing value placed on discovering the most challenging and impactful security vulnerabilities in today’s threat landscape.


