Skip to main content
  1. Home
  2. Phones
  3. Android
  4. Mobile
  5. News

Google’s Android bug bounty program announces a $1 million prize

Add as a preferred source on Google

Google has been handing out cash rewards to Android bug hunters since 2015 in an effort to keep the mobile operating system safe and secure and running smoothly.

This week the Mountain View, California-based company announced it is increasing its top payout to a whopping $1 million, with a potential for a 50% bonus that pushes it to $1.5 million.

Recommended Videos

Suffice to say, that kind of money means Google is talking about a particular kind of hack, specifically a “full chain remote code execution exploit with persistence which compromises the Titan M secure element on Pixel devices.” Broadly speaking, it means cracking the Titan M chip on a Pixel phone without having physical access to the device. The $500,000 bonus is being offered for exploits found on specific developer preview versions Android.

Google started using the Titan M chip with its Pixel 3 smartphones that launched in 2018. The company describes it as an enterprise-grade security chip designed to secure the user’s most sensitive on-device data, as well as the device’s operating system. For example, Titan M helps the bootloader — the program that validates and loads Android when the phone turns on — ensure you’re running the right version of Android. It also verifies your lock screen passcode and secures transactions in third-party apps.

A bounty worth a million bucks — and more — should ensure the challenge gets plenty of attention among those with the know-how. Dealing with any exploits will allow Google to further bolster the security of its Pixel devices and avoid potential trouble from more malevolent hackers further down the road.

Google payouts

Google said that since it launched the Android Security Rewards program in 2015, it has awarded over 1,800 reports and paid out more than $4 million.

Total payouts in the past year alone amounted to $1.5 million.

“Over 100 participating researchers have received an average reward amount of over $3,800 per finding (46% increase from last year),” Jessica Lin of the Android Security Team wrote in a blog post this week, adding, “On average, this means we paid out over $15,000 (20% increase from last year) per researcher.”

Google’s largest single payment to date saw a bug hunter receive just over $160,000 in 2019 for uncovering a Pixel 3 exploit.

Last year we heard how an 18-year-old whiz-kid picked up $36,000 from Google after discovering a vulnerability that could have allowed a hacker to make changes to the company’s internal computer systems.

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
This new technology could make spotting fake products easier for everyone
Your smartphone could soon tell you if the product you bought is fake
The new system combines three technologies into a single printable label.

Counterfeit goods are becoming increasingly sophisticated, forcing brands to rely on expensive authentication systems that often require specialized scanners or proprietary hardware. Researchers now believe a smartphone could do much of that work instead. A team has developed a new printing system that creates responsive anti-counterfeit labels that are more durable, easier to mass-produce, and can be verified using nothing more than a phone. The research was published in the International Journal of Materials and Product Technology.

At first glance, the technology looks like another incremental improvement in product security. In reality, it addresses one of the biggest limitations of anti-counterfeit systems today: accessibility. If authentication only works with expensive equipment, it becomes difficult to deploy at scale. By enabling smartphone-based verification, the technology could make counterfeit detection practical for manufacturers, retailers, and even consumers.

Read more
Apple’s iPhone Air could serve as the blueprint for its 20th anniversary iPhone
Fresh leaks suggest Apple's 20th anniversary iPhone will combine an Air-inspired frame.
iPhone Air Featured

The iPhone Air is often dismissed as an experiment that didn’t achieve the same success as Apple’s other products.

However, a fresh leak suggests Apple may view the slim iPhone differently, treating its design language as something that could eventually make its way into the mainstream lineup.

Read more
Sunbird relaunches its iMessage app for Android, three years after a privacy scandal shut it down
Sunbird returns to Android with fixed encryption and an AI assistant on the way.
sunbird-imessage-app-relaunch-2026

Sunbird's blue bubble dream for Android users is making another attempt, and this time the company insists it's actually earned your trust. Sunbird Messaging, the app that lets Android users join iMessage conversations without the green bubble stigma, is now available on the Google Play Store after sitting dormant since 2023.

Back then, security researchers discovered the app was sending Apple ID credentials over unencrypted connections and quietly logging user messages through a debugging tool, despite Sunbird's public claims of full end-to-end encryption. The fallout forced both Sunbird and its Nothing Phone partnership to shut down almost overnight.

Read more