Google now offers up to $1.5 million for some Android exploits

Google has significantly revamped its Android and Chrome vulnerability rewards programs, introducing substantially higher bounties for the most complex security discoveries while adjusting rewards for vulnerabilities that artificial intelligence (AI) has simplified to identify.

The technology giant now offers rewards of up to $1.5 million for the most sophisticated Android exploits – specifically zero-click attacks targeting the Pixel Titan M2 security chip that achieve full-chain compromise with persistence capabilities. For similar exploits without persistence mechanisms, researchers can still earn up to $750,000.

In the Chrome vulnerability program, full-chain browser process exploits targeting up-to-date systems and hardware now qualify for rewards reaching $250,000, with an additional $250,128 bonus available for successfully exploiting MiraclePtr-protected memory allocations.

Google has shifted its focus toward concise security reports containing only essential bug proofs and technical artifacts, moving away from lengthy written analyses that AI systems can now generate automatically. This approach ensures researchers concentrate on genuine discovery rather than documentation that could be automated.

For Android-specific submissions, the program prioritizes Linux kernel vulnerabilities within Google-maintained components, unless researchers can provide concrete evidence of exploitability on actual Android devices.

These program enhancements follow a record-breaking year for Google’s bug bounty initiatives, with the company distributing $17.1 million to 747 security researchers in 2025 – representing a 40% increase from 2024 and establishing a new all-time high. Since the vulnerability rewards program launched in 2010, cumulative payouts have exceeded $81.6 million.

Google anticipates that total aggregate rewards for 2026 will continue growing despite reductions in certain individual bounty amounts, reflecting the increasing value placed on discovering the most challenging and impactful security vulnerabilities in today’s threat landscape.

spot_imgspot_img

Subscribe

Related articles

Karakurt extortion gang ‘cold case’ negotiator gets 8.5 years in prison

Latvian national sentenced to 8.5 years for Karakurt ransomware negotiator role in $56M+ extortion scheme.

Test Post Updated

This test post has been updated.

Weekly Deals: iPhone Air and iPhone 17 Price Cuts, Galaxy S26 and Pixel 10 Series on Sale

This Week's Best Smartphone DealsThe flagship smartphone market is...

Apple Unveils 2026 Pride Edition Sport Loop — A Rainbow Woven for Every Identity

A Band That Celebrates the Full SpectrumApple has launched...

Google Gemini App Gets a Stunning Makeover on iOS — Here is What is New

A Fresh Look for Google's AI Assistant on iPhoneGoogle...
spot_imgspot_img