IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Google to offer $1.5m to anyone that can break a Pixel 4

In a bid to make its Titan technology more secure, Google takes a page out of Apple's playbook

Google has expanded its Android bug bounty program to match the $1.5 million (£1.17m) payout Apple offers for bugs found in its flagship smartphones.

The Titan M security layer, which features in Google's latest Pixel 4 smartphone, is now included as part of the company's bounty list, with the discovery of a working remote-code execution (RCE) bug being worth a potential $1 million (£776,900).

The bug hunter will be eligible for an additional 50% bonus if the Titan M vulnerability is detected and provided to Google in a developer preview version of Android, taking the maximum reward up to $1.5 million.

Aside from Titan M, Google’s Android Security Reward Program will also continue to offer rewards to researchers who find vulnerabilities in other hardware.

Up to $500,000 (£388,365) will be awarded to those who can find bugs relating to issues such as unauthorised data exfiltration and bypassing of the Pixel’s lock screen. The 50% developer preview bonus also applies to these vulnerabilities.

Google has invested heavily in its proprietary Titan technology in recent years, adding its functionality to many of its products as a more secure method of account authentication compared to 2FA.

It’s designed to offer Google hardware owners better security by assigning a physical security layer to an account, meaning remote attackers can’t intercept authenticator codes or mimic approval actions of the true owner.

Despite the faith that Google has placed in its Titan technology, it has been proven in the past to be less than iron-clad.

Earlier this year, a security flaw was found in a version of Google’s Titan Key, a physical device outside of the Pixel line that authenticates account log-in. 

It only affected the Bluetooth pairing protocol needed to pair the key with the device through which the account was being accessed and Google said it would offer free replacements for the faulty units worth $50.

The bounty rewards have been increased to match Apple’s own bug bounty program which itself expanded earlier this year.

Apple also offers a maximum reward of $1 million with a 50% bonus for bugs found during an iOS beta phase.

Apple announced the expansion at Black Hat 2019 along with the news that select researchers could apply for specially crafted iPhones that would make it easier for them to detect vulnerabilities.

Featured Resources

The state of Salesforce: Future of business

Three articles that look forward into the changing state of Salesforce and the future of business

Free Download

The mighty struggle to migrate SAP to the cloud may be over

A simplified and unified approach to delivering Enterprise Transformation in the cloud

Free Download

The business value of the transformative mainframe

Modernising on the mainframe

Free Download

The Total Economic Impact™ Of IBM FlashSystem

Cost savings and business benefits enabled by FlashSystem

Free Download

Most Popular

Why convenience is the biggest threat to your security
Sponsored

Why convenience is the biggest threat to your security

8 Aug 2022
How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

29 Jul 2022
Cyber attack on software supplier causes "major outage" across the NHS
cyber attacks

Cyber attack on software supplier causes "major outage" across the NHS

8 Aug 2022