HomeSecurityGoogle offers up to $1.5 million for Android exploits

Google is offering up to $1.5 million for Android exploits

Google has overhauled its vulnerability bounty programs in Android and Chrome, offering rewards of up to $1.5 million for the most difficult exploits, while reducing payments for weaknesses that artificial intelligence (AI) has made easier to spot.

See also: WhatsApp: Italian spyware company created fake iOS version

Google

The highest reward of $1.5 million is for a full-chain exploit of the Pixel Titan M2 without the need for user interaction and with access retention, the most technically demanding attack scenario in the program. The same exploits, but without access retention, are also eligible for up to $750,000.

For the Google Chrome program, full browser process chain exploits on updated operating systems and hardware now come with rewards of up to $250,000 , plus an additional $250,128 bonus for successfully exploiting MiraclePtr -protected memory allocations .

“ We know that some particularly important exploits remain extremely difficult to achieve, and we greatly appreciate the collaboration with the research community in discovering and disclosing them ,” Google said

See also: “WhatsApp malware” campaign uses malicious VBS files

Google is offering up to $1.5 million for Android exploits

“We want to strengthen this partnership by continuing to emphasize the highest levels of rewards for both Android and Chrome.“

Google is shifting its focus for the Chrome program to concise reports containing only bug evidence and key artifacts, rather than the extensive written analyses that AI can now generate automatically. The Android program will also focus on Linux kernel vulnerabilities in assets Google maintains, unless researchers can demonstrate specific exploitability on Android devices.

“While AI has made it easy to produce extensive, detailed reports, our internal tools have also evolved to help us automatically explain and suggest fixes for errors,” the company added.

See also: WhatsApp: New AI features and other improvements

Google is offering up to $1.5 million for Android exploits

This restructuring of the vulnerability bounty program follows a record year for Google’s bug bounty effort, with the company paying $17.1 million to 747 researchers in 2025, an increase of more than 40 percent from 2024 and an all-time high. This brings total payouts since the program began in 2010 to more than $81.6 million, and Google estimates that total rewards paid in 2026 will increase despite decreases in some individual reward amounts.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS