Google Raises Top Android Bug Bounty to $1.5 Million to Combat AI-Era Threats

Closeup shot of a Google's Pixel 10a held in a hand.
Google is adjusting its bug bounty payout amounts for Android and Chrome security flaws, and the top reward could make you a millionaire. The hope is that a $1.5 million payment will incentivize white hat hackers and security researchers to help the company harden its defenses in Android as the AI era unfolds, presenting and new and novel threats.

The adjusted payout figures arrive six months after Google flagged an AI malware surge, as hackers begin leveraging large language models to develop malicious code capable of mutating on the fly. Now half a year later, Google says it wants to continue rewarding researchers for their ability to root out challenging and hard to find security vulnerabilities within its products and services.

"Over the past few years, AI and automation have accelerated the pace of vulnerability discovery, and our teams are moving at an unprecedented rate – remediating risks more effectively than ever before. The latest advancements in AI from Google and the broader industry have made it significantly easier to take a test case and explain the root cause, propose a suitable fix, and to find variants of known problems," Google says.

Table of bounty payments for Google's Android platform.

As the security landscape evolves with AI, Google want to make sure its rewards programs reflect the modern era. For Android flaws, the top payout is now $1.5 million, which applies to the discovery of a zero-click full chain Pixel Titan M2 compromise with persistence. Without persistence, the reward is cut in half to $750,000. Google's Titan M2 coprocessor is found on a range of Tensor-powered Pixel phones, including the Pixel 10a.

Neither of those make for a bad payday for a single vulnerability. They also represent big payment bumps—previously, the top payout was $1 million, while a top payout for a flaw without persistence was $500,000. Google's also paying up to $375,000 for secure element data exfiltration flaws, up from $250,000 previously.

Google adjusted its top Chrome bounties too, though they shifted in the opposite direction. However, they're still lucrative with Google paying up to $250,000 for full-chain browser process exploits on the latest operating systems and hardware, along with up to a $250,128 bonus for a report that successfully exploits an allocation it believes is protected by MiraclePtr.

"We are revising our program scope to emphasize categories that represent the highest risk to our users. We are also prioritizing categories that remain more challenging for automated AI tooling to find to ensure we reward researchers for their unique skills and talents," Google explains.

For a full list of reward amounts and other details, check out Google's Android vulnerability and Chrome vulnerability bounty pages.
Paul Lilly

Paul Lilly

Paul is a seasoned geek who cut this teeth on the Commodore 64. When he's not geeking out to tech, he's out riding his Harley and collecting stray cats.