
Google boosts Android/Chrome bug-bounty rewards to as high as $1.5M
Google overhauls its Android and Chrome vulnerability rewards programs, elevating top Android payouts to $1.5 million for zero-click full-chain exploits on the Pixel Titan M2 (with up to $750,000 for non-persistent variants) and offering up to $250,000 for Chrome full-chain exploits plus a $250,128 bonus for MiraclePtr-protected memory allocations; the changes push for concise bug proofs instead of lengthy analyses and narrow Android focus to Linux kernel vulnerabilities in Google components unless researchers demonstrate device exploitability. The revamp follows a record 2025 with $17.1 million paid to 747 researchers, bringing total payouts since 2010 over $81.6 million, and 2026 totals are expected to rise despite some reductions.
