Zero-day exploit broker Zerodium increases the price of a “zero-click” exploit chain for Android to $2.5M, eclipsing iOS' top prize for the first time
Context & Ripple Effects
Zerodium has been publishing a public price list since 2015, when cracking an Android phone fetched just $100K against $500K for iOS (its original hack price list). In 2016 it widened the gap by tripling the iOS bounty to $1.5M while doubling Android's to only $200K (the 2016 bounty reset).
The new $2.5M top prize for an Android zero-click chain inverts that hierarchy for the first time. It lands weeks after Google Project Zero published demo code for five of six 'interactionless' iOS bugs (the interactionless iOS disclosures), a reminder of how quickly brokered prices track which platforms are actually being attacked.
First-order effects
- Researchers holding working Android zero-click chains can now command more from Zerodium than from any iOS submission, redirecting elite exploit supply toward Android.
- Government and corporate buyers sourcing through Zerodium effectively signal that Android intrusion capability is what they currently cannot get elsewhere.
Second-order effects
- Google faces a pricier black-market target on its platform, raising the stakes for its own vulnerability rewards and patch cadence relative to Apple's.
- Apple gains a reputational data point: as long as its top prize stays below Android's, Zerodium's list doubles as marketing for iOS hardening.
Third-order effects
- If broker price lists keep functioning as a live index of platform attack difficulty, mobile OS vendors will be benchmarked publicly on exploit economics, not just patch counts — with pricing pressure shifting toward whichever ecosystem attackers find softer.
The trend: Exploit brokers' published bounties are becoming a real-time market index of which mobile platforms are hardest — or easiest — to break.