/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

$1M bug bounty offered for exclusive, browser-based, untethered iOS9 jailbreak by Zerodium, a startup selling zero-day exploits to governments and corporations

Andy Greenberg / Wired :

Wired Andy Greenberg

Context & Ripple Effects

Zerodium, a startup whose business is buying zero-day exploits and reselling them to governments and corporations, is putting a public price on Apple's mobile security: $1M for an exclusive, browser-based, untethered iOS9 jailbreak. The specificity matters — the bounty rewards a full remote chain that needs no physical access, not just any crash or partial bypass.

This announcement effectively opened a published market for iOS exploit prices. Within a year Zerodium had tripled its top iOS prize to $1.5M, and by 2019 an Android zero-click chain at $2.5M overtook iOS for the first time — an escalation arc this 2015 bounty set in motion. Meanwhile, flaws of exactly the kind being bought here surfaced in the wild against activists via NSO-linked malware before Apple patched them in iOS 9.3.5.

First-order effects

  • Security researchers holding a working iOS9 browser-based jailbreak now face a direct choice between Zerodium's seven-figure payout and responsible disclosure to Apple, which pays nothing comparable.
  • Apple gains a new adversary dynamic: the exact exploit class it most fears — remote, untethered compromise — now has a standing cash price attached, raising the odds such chains reach government and corporate buyers instead of the vendor.

Second-order effects

  • Rival brokers and buyers must respond to the price signal: Zerodium's own subsequent raises to $1.5M for iOS and $200K for Android show the bounty level functioning as a competitive floor that keeps ratcheting upward.
  • The existence of a liquid resale market pushes adjacent players like Google Project Zero toward rapid publication of interactionless iOS bugs — flooding research into the open partly to deny brokers exclusivity.

Third-order effects

  • Vulnerability discovery is structurally splitting into two economies — one paying vendors' goodwill and reputation, the other paying brokers' published price lists — and the gap between them, already $1M versus $0 in 2015, determines where critical mobile bugs land.
  • As zero-click chains come to command the highest prices, platform security competition shifts from blocking individual bugs to raising the cost of full remote exploit chains, with broker price lists becoming a rough public index of which platforms are hardest to break.

The trend: Mobile zero-day exploits are turning into a priced commodity market, with broker bounties rising steadily since 2015 and steering researchers away from disclosure toward government and corporate buyers.