Exploit broker Zerodium triples bounty to $1.5M for iOS, and doubles bounty for Android to $200K
Zerodium triples price for iOS exploits, doubles Android bounties to $200,000. — A controversial broker of security exploits is offering $1.5 million (£1.2 million) …
Context & Ripple Effects
Zerodium has been ratcheting prices all year: after offering a $1M bounty for an iOS9 jailbreak last year, it published a price list putting iOS cracks at $500K and Android or Windows Phone at $100K. Today's move triples the iOS figure to $1.5M and doubles Android to $200K, a steep repricing of the same targets within twelve months.
The broker sells exclusively to governments and corporations, so its price sheet functions as a public read on what state buyers will pay for mobile access. The trajectory continued afterward: by 2019 Zerodium paid $2.5M for a zero-click Android exploit chain, briefly eclipsing iOS for the first time.
First-order effects
- Researchers with working iOS or Android chains can now command three to five times the payouts Zerodium offered a year ago, tightening the broker's supply of exclusive exploits against rival buyers.
Second-order effects
- Apple and Google face a widening gap between gray-market prices and their own bug bounty rates, pressure that eventually showed when Apple doubled its top award to $2M for spyware-capable chains in its 2025 Security Bounty overhaul.
Third-order effects
- If broker pricing keeps compounding faster than vendor bounties, the zero-day market structurally favors government stockpiles over defensive disclosure, forcing platform makers to keep scaling official rewards as the counterweight.
The trend: Mobile zero-day pricing is on a decade-long climb from six to seven figures, with brokers like Zerodium setting the market rate and vendors like Apple chasing it with ever-larger official bounties.