Exploit broker Zerodium triples bounty to $1.5M for iOS, and doubles bounty for Android to $200K
Dan Goodin / Ars Technica :
Context & Ripple Effects
Zerodium's new price list is a sharp escalation of a market it has been repricing for a year: it paid out on its $1M iOS9 jailbreak bounty in late 2015, then published a list valuing an iOS crack at $500K against just $100K for Android or Windows Phone. Tripling iOS to $1.5M and doubling Android to $200K widens that gap further.
First-order effects
- Researchers holding working iOS exploit chains now face a choice between Zerodium's $1.5M and vendor programs paying far less, pulling supply of fresh zero-days toward government buyers.
- Android's $200K ceiling still prices it as a second-tier target in Zerodium's book, signaling to researchers where exclusive submissions are worth the most.
Second-order effects
- Vendors must either match broker rates or lose top-tier bugs to them — a pressure that later shows up in Google's move to pay up to $1.5M for Titan M secure-element exploits on Pixels (rewards that used to top out at $200K) and Apple's eventual doubling of its own top award to $2M (for spyware-abusable exploit chains).
- Higher bounties raise the acquisition cost for any government or corporate customer buying through brokers, pushing buyers toward longer, more valuable chains rather than single bugs.
Third-order effects
- If the pattern holds, exploit pricing becomes a standing auction between brokers and vendors, with platform security budgets set by what intermediaries will pay — and by 2019 Zerodium's $2.5M zero-click Android chain had already overtaken iOS as its priciest target, showing how quickly the hierarchy can flip.
The trend: Zero-day pricing is shifting from a broker's private rate card into a competitive market that directly sets the reference price vendors must beat to keep vulnerabilities in-house.