Google increases Chrome bug bounty rewards, tripling the maximum baseline reward from $5,000 to $15,000 and doubling the maximum reward from $15,000 to $30,000
Context & Ripple Effects
This raise extends a pricing ladder Google has climbed before: back in 2016 it doubled the top Chromebook hack reward to $100,000 after zero successful submissions, using money to seed a market that barely existed [[a:866414]]. By mid-2019 the Chrome program needed a different fix — keeping steady-state rewards competitive once researcher flow was established.
The timing sits inside a broader 2019 bounty push at Google, which within weeks spread the model beyond the browser to Android apps and data-abuse findings. The later program stats make the logic legible: enough volume accumulated that per-bug pricing became a real lever on where researchers spend their hours.
First-order effects
- Security researchers filing qualifying Chrome flaws see the payout curve jump immediately — the baseline cap triples to $15,000 and the overall cap doubles to $30,000, changing which vulnerabilities clear the bar for a report.
- For Google, the higher table reprices its own defensive spend: paying up to $30,000 per bug becomes the cost of keeping disclosures flowing through its program rather than elsewhere.
Second-order effects
- The raise set the template for the rest of Google's 2019 expansion — weeks later the program covered Play apps with over 100 million installs plus data abuses in Android apps and Chrome extensions, carrying the new price signal across the Android ecosystem.
- Researchers weighing Chrome against other Google targets now face shifted relative pay, concentrating attention on the browser just as the company widened the program to adjacent surfaces.
Third-order effects
- If the pattern holds, bounties function as standing security procurement rather than ad hoc rewards: by 2021 Google reported 11,055 bugs found and roughly $30M paid out [[a:968973]], and by 2022 it extended the model specifically to open source dependencies.
- The same structure eventually reached Google's newest attack surface, with a dedicated AI bounty in 2025 offering up to $30K for prompt injections and alignment issues — capping a decade in which each new product line inherited the bounty mechanism.
The trend: Bug bounties are hardening into a permanent procurement channel that Google re-prices and extends with each new layer of its stack, from the Chrome browser through Android to AI models.