Google is trying to move researcher effort away from high-volume, AI-generated bug reports and toward bugs that are actually exploitable on real devices. The standard response of filing long writeups is losing value; Google now wants concise proof, concrete artifacts, and, for many issues, a proposed patch.
The Android and Google Devices VRP now prioritizes high-user-impact flaws and categories that are harder for AI tools to find. Google also raised top payouts for zero-click Pixel Titan M exploits with persistence to $1.5 million, lifted secure element data exfiltration to $375,000, and said Linux kernel reports need concrete proof of exploitability on Android or Google devices before they get the best treatment.
For Chrome, base rewards for memory safety issues have dropped to $500 with multipliers tied to reachability and exploitability. The practical shift is economic: Google is paying more for device-level compromise and less for broad, low-signal submissions, which should change what researchers spend time on and what defenders see first.