Google to offer $1.5m to anyone that can break a Pixel 4
In a bid to make its Titan technology more secure, Google takes a page out of Apple's playbook


Google has expanded its Android bug bounty program to match the $1.5 million (£1.17m) payout Apple offers for bugs found in its flagship smartphones.
The Titan M security layer, which features in Google's latest Pixel 4 smartphone, is now included as part of the company's bounty list, with the discovery of a working remote-code execution (RCE) bug being worth a potential $1 million (£776,900).
The bug hunter will be eligible for an additional 50% bonus if the Titan M vulnerability is detected and provided to Google in a developer preview version of Android, taking the maximum reward up to $1.5 million.
Aside from Titan M, Google’s Android Security Reward Program will also continue to offer rewards to researchers who find vulnerabilities in other hardware.
Up to $500,000 (£388,365) will be awarded to those who can find bugs relating to issues such as unauthorised data exfiltration and bypassing of the Pixel’s lock screen. The 50% developer preview bonus also applies to these vulnerabilities.
Google has invested heavily in its proprietary Titan technology in recent years, adding its functionality to many of its products as a more secure method of account authentication compared to 2FA.
It’s designed to offer Google hardware owners better security by assigning a physical security layer to an account, meaning remote attackers can’t intercept authenticator codes or mimic approval actions of the true owner.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Despite the faith that Google has placed in its Titan technology, it has been proven in the past to be less than iron-clad.
Earlier this year, a security flaw was found in a version of Google’s Titan Key, a physical device outside of the Pixel line that authenticates account log-in.
It only affected the Bluetooth pairing protocol needed to pair the key with the device through which the account was being accessed and Google said it would offer free replacements for the faulty units worth $50.
The bounty rewards have been increased to match Apple’s own bug bounty program which itself expanded earlier this year.
Apple also offers a maximum reward of $1 million with a 50% bonus for bugs found during an iOS beta phase.
Apple announced the expansion at Black Hat 2019 along with the news that select researchers could apply for specially crafted iPhones that would make it easier for them to detect vulnerabilities.

Connor Jones has been at the forefront of global cyber security news coverage for the past few years, breaking developments on major stories such as LockBit’s ransomware attack on Royal Mail International, and many others. He has also made sporadic appearances on the ITPro Podcast discussing topics from home desk setups all the way to hacking systems using prosthetic limbs. He has a master’s degree in Magazine Journalism from the University of Sheffield, and has previously written for the likes of Red Bull Esports and UNILAD tech during his career that started in 2015.
-
CISA issues warning in wake of Oracle cloud credentials leak
News The security agency has published guidance for enterprises at risk
By Ross Kelly
-
Reports: White House mulling DeepSeek ban amid investigation
News Nvidia is caught up in US-China AI battle, but Huang still visits DeepSeek in Beijing
By Nicole Kobie
-
Should your business start a bug bounty program?
In-depth Big tech firms including Google, Apple and Microsoft offer bug bounty programs, but can they benefit smaller businesses too?
By Kate O'Flaherty
-
OpenAI to pay up to $20k in rewards through new bug bounty program
News The move follows a period of unrest over data security concerns
By Ross Kelly
-
Windows 11 System Restore bug preventing users from accessing apps
News Microsoft has issued a series of workarounds for the issue which is affecting a range of apps including Office and Terminal
By Ross Kelly
-
Windows 10 users encounter ‘blue screen of death’ after latest Patch Tuesday update
News Microsoft said it is working on a fix for the issue and has offered users a temporary workaround
By Ross Kelly
-
SpaceX bug bounty offers up to $25,000 per Starlink exploit
News The spacecraft manufacturer has offered white hats immunity to exploit a wide range of Starlink systems, with a dedicated report page
By Rory Bathgate
-
Microsoft announces lucrative new bug bounty awards for M365 products and services
News The new awards will focus on scenario-based weaknesses and offer bonuses of up to 30% for the most severe bugs
By Connor Jones
-
Adobe forced to patch its own failed security update
News Company issues new fix for e-commerce vulnerability after researchers bypass the original update
By Danny Bradbury
-
Google doubles bug bounty rewards for Linux, Kubernetes exploits
News The increased rewards are said to align better with the community's expectations of a bug bounty programme of this kind
By Connor Jones