Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Management & Strategy

Google Offering Up to $1.5 Million for Pixel Titan M Exploits

Google on Thursday announced that it’s expanding its Android bug bounty program, and certain types of exploits can now earn researchers up to $1.5 million

Google on Thursday announced that it’s expanding its Android bug bounty program, and certain types of exploits can now earn researchers up to $1.5 million

According to Google, it has paid out over $4 million for more than 1,800 vulnerability reports received since the launch of its Android Security Rewards program in 2015. In the past year, payouts totaled over $1.5 million and the highest single reward paid out in 2019 was just over $161,000.

The highest reward this year was paid out to Guang Gong of the Chinese cybersecurity firm Qihoo 360. In fact, the researcher earned over $200,000 for a single exploit chain as he demonstrated how an attacker could remotely execute arbitrary code on a Pixel 3 device using a combination of Android and Chrome vulnerabilities — the Chrome flaws earned him an extra $40,000. Only one click was required to trigger his exploit.

Google has now announced significantly higher rewards through the Android Security Rewards program, including up to $1 million for a Pixel Titan M exploit, which is also eligible for a 50% bonus if the exploit chain works on certain developer preview versions of Android. Google is offering the top reward for a full chain remote code execution exploit that provides persistence on the device and involves compromising the company’s Titan M security chip.

White hat hackers who demonstrate a method for exfiltrating data protected by the Pixel Titan M chip can now earn up to $500,000, and up to $250,000 for exfiltrating data secured by a Secure Element.

Another new category added to the Android bug bounty program covers lockscreen bypass techniques. Researchers can earn up to $100,000 for these types of attacks.

Advertisement. Scroll to continue reading.

It’s worth noting that exploit acquisition firm Zerodium, which claims to provide its services mainly to government organizations, is currently offering up to $2.5 million for an Android exploit chain the requires no clicks and ensures persistence on the targeted device. An iOS exploit chain that requires one click and offers persistence on the device is worth up to $2 million.

Related: Google Offers Big Bounties for Data Abuse Reports

Related: Unpatched Privilege Escalation Vulnerability Impacts Android

Related: Google Offers Bonus Bounties for Flaws in Popular Android Apps

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Rapid7 has named Rik Ferguson as VP of Security Intelligence.

Cytactic has appointed Tim Brown as CSO.

Scott Simkin has joined Vega as CMO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.