Google increases rewards for Titan M secure element exploits on Pixels to $1.5M and to $750K for other exploits; Android hack rewards used to top out at $200K
Dan Goodin / Ars Technica :
Context & Ripple Effects
Google's Android bounty has been climbing in steps for years: it first extended security rewards to device bugs with Nexus 6 and Nexus 9 in 2015, then doubled the Chromebook top prize to $100K in 2016 after zero successful submissions, and raised Chrome's own ceilings earlier in 2019. The new structure — $1.5M for Titan M secure element exploits on Pixels, $750K for other Android exploits against a former $200K cap — is by far the largest step in that sequence.
The move also reorders Google's internal bounty hierarchy: its Mobile Vulnerability Rewards Program for Android apps tops out at $30K, so the flagship payouts now sit almost entirely at the hardware-adjacent layer rather than the application layer.
First-order effects
- Security researchers weighing where to spend effort see a 7.5x higher ceiling on general Android exploits ($200K to $750K), making Pixel attack chains suddenly competitive with platform-level bug hunting.
- Titan M becomes the single highest-paying target in Google's ecosystem — a direct signal that Google prices compromise of its secure element above any software-only vulnerability.
Second-order effects
- Research talent and brokered exploit sales shift toward Pixel hardware attacks, starving lower-tier surfaces like the Play-app bounty ($1K–$30K range) of attention unless those programs raise their own ceilings in response.
- Rivals shipping their own secure elements face implicit benchmark pressure: Google's published price for breaking Titan M sets a reference point buyers and enterprises can use to compare hardware security claims.
Third-order effects
- If the escalation pattern holds — each round of raises following thin or stalled submissions, as with the Chromebook doubling — bounty pricing hardens into a market signal, with Google effectively auctioning for attacker time and treating payout tables as security marketing.
- Hardware-backed security consolidates as the premium tier of the bug economy: software-layer programs (apps, AI prompt injection) stay an order of magnitude cheaper than silicon-rooted ones, structuring the research market around who controls the root of trust.
The trend: Google's bounty ceilings have ratcheted steadily since 2015, and this jump marks the point where hardware secure elements — not browsers or apps — become the top-priced attack surface in its programs.