$1M bug bounty offered for exclusive, browser-based, untethered iOS9 jailbreak by Zerodium, a startup selling zero-day exploits to governments and corporations
Context & Ripple Effects
Zerodium, a startup whose business is buying zero-day exploits and reselling them to governments and corporations, is putting a public price on Apple's mobile security: $1M for an exclusive, browser-based, untethered iOS9 jailbreak. The specificity matters — the bounty rewards a full remote chain that needs no physical access, not just any crash or partial bypass.
This announcement effectively opened a published market for iOS exploit prices. Within a year Zerodium had tripled its top iOS prize to $1.5M, and by 2019 an Android zero-click chain at $2.5M overtook iOS for the first time — an escalation arc this 2015 bounty set in motion. Meanwhile, flaws of exactly the kind being bought here surfaced in the wild against activists via NSO-linked malware before Apple patched them in iOS 9.3.5.
First-order effects
- Security researchers holding a working iOS9 browser-based jailbreak now face a direct choice between Zerodium's seven-figure payout and responsible disclosure to Apple, which pays nothing comparable.
- Apple gains a new adversary dynamic: the exact exploit class it most fears — remote, untethered compromise — now has a standing cash price attached, raising the odds such chains reach government and corporate buyers instead of the vendor.
Second-order effects
- Rival brokers and buyers must respond to the price signal: Zerodium's own subsequent raises to $1.5M for iOS and $200K for Android show the bounty level functioning as a competitive floor that keeps ratcheting upward.
- The existence of a liquid resale market pushes adjacent players like Google Project Zero toward rapid publication of interactionless iOS bugs — flooding research into the open partly to deny brokers exclusivity.
Third-order effects
- Vulnerability discovery is structurally splitting into two economies — one paying vendors' goodwill and reputation, the other paying brokers' published price lists — and the gap between them, already $1M versus $0 in 2015, determines where critical mobile bugs land.
- As zero-click chains come to command the highest prices, platform security competition shifts from blocking individual bugs to raising the cost of full remote exploit chains, with broker price lists becoming a rough public index of which platforms are hardest to break.
The trend: Mobile zero-day exploits are turning into a priced commodity market, with broker bounties rising steadily since 2015 and steering researchers away from disclosure toward government and corporate buyers.