logo

Google now offers up to $1.5 million for some Android exploits

ID: 78b3753d-5a1b-51f7-9575-d8f4d3636e7a

STIX ID: report--78b3753d-5a1b-51f7-9575-d8f4d3636e7a

Feed Name: Bleeping Computer

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: Sergiu Gatlan

...
...

Google announced an overhaul of its Android and Chrome vulnerability rewards programs: top payouts rise (up to $1.5M for Pixel Titan M2 full-chain persistent exploits, up to $250K plus bonuses for Chrome full-chain exploits) while rewards are scaled back for flaws that AI has made easier to find. The Chrome program will prefer concise POCs over long write-ups and Android payouts will focus on Linux kernel issues in Google-maintained components unless exploitability on Android devices is demonstrated; the change follows record-year bounty payments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.