Drooid Logo
Back to story perspectives

Full Breakdown

Google Overhauls Android and Chrome Vulnerability Reward Programs

5/6/2026, 10:47:39 PM

Revised Bounty Structure Targets High-Risk Exploits

Google announced a major revision to its Android and Chrome Vulnerability Reward Programs (VRPs). The top bounty for a zero-click, full-chain compromise of a Pixel device that persists on the Titan M2 security chip now reaches $1.5 million, with a non-persistent version capped at $750 000. Full-chain Chrome browser process exploits on the latest OS and hardware can earn up to $250 000, plus a $250 128 MiraclePtr bonus. At the same time, payouts for lower-complexity Android and Chrome bugs have been reduced, and bonuses for renderer remote-code execution and arbitrary read/write vulnerabilities have been eliminated.

Background: AI-Driven Shift in Vulnerability Research

The changes follow Google’s 2025 launch of an AI-focused bug bounty covering Gemini, Search, and Workspace tools, where researchers can receive up to $30 000 for serious AI-related flaws. Google notes that AI tools now automate the discovery of simple bugs, prompting a strategic move toward rewarding findings that require deeper technical skill and pose real-world risk.

Data & Statistics

  • $1.5 M maximum for persistent zero-click Pixel/Titan M2 exploits (previously $1 M).
  • $750 k for non-persistent versions of the same exploit chain.
  • $250 k for full-chain Chrome exploits; $250 128 MiraclePtr bonus remains.
  • Removal of renderer RCE and arbitrary read/write bonuses.
  • AI bug bounty caps at $30 k per qualifying AI-related flaw.
  • Google expects the total 2026 reward pool to increase despite lower payouts for basic bugs.

Official Statements & Responses

Google said the revision focuses on categories that pose the greatest risk to users and gives priority to those that remain difficult for automated AI tools to detect. The company added that AI has turned simple vulnerability reports into routine matters, prompting a focus on concise, reproducible findings with clear impact. Google also highlighted new Chrome builds for researchers to demonstrate memory-access issues and encouraged submissions that include patch proposals.

Verbatim Quotes

  • “We are revising our program scope to emphasize categories that represent the highest risk to our users,” — Google spokesperson
  • “We are also prioritizing categories that remain more challenging for automated AI tooling to find.” — Google spokesperson
  • “While AI has made it easier to produce lengthy, detailed write-ups, our internal tooling has also evolved to help us automatically explain and suggest fixes for bugs,” — Google spokesperson

What’s Next: Ongoing Adjustments and Expanded AI Coverage

Google indicated that the 2026 reward pool will grow, reflecting higher payouts for complex exploits. The AI bug bounty program, launched in 2025, will continue to accept reports on emerging generative-AI products, with the expectation that future VRP updates will further align incentives with evolving threat landscapes and research capabilities.