Guide
Apple vs Google bug bounty programs
The Apple Security Bounty and Google's Vulnerability Reward Program are the two most recognisable bug bounty programs in the industry, and they are built on opposite bets. Apple pays enormous sums for a very small set of deep platform findings. Google pays smaller amounts across an enormous surface. Which one is worth your time depends on how long you can afford to work on a single target.
Side-by-side comparison
Program name
- Apple
- Apple Security Bounty
- Google
- Google Vulnerability Reward Program (VRP)
Headline maximum
- Apple
- Up to $2,000,000 for a zero-click remote chain, with published multipliers for Lockdown Mode bypasses and beta findings.
- Google
- Up to $151,515 for a full Android remote chain, with separate VRP tracks for Chrome, Cloud, and AI products.
Scope
- Apple
- Narrow and platform-owned: iOS, iPadOS, macOS, watchOS, tvOS, visionOS and iCloud. Apple defines categories by impact tier rather than by asset list.
- Google
- Broad: every Google-owned web property, Android, Chrome, Workspace, Google Cloud, plus open-source projects under a separate OSS VRP.
Report quality bar
- Apple
- Requires a working proof of concept on current software. Theoretical impact is routinely rejected.
- Google
- Accepts well-reasoned reports without full exploitation, but reward size scales sharply with demonstrated impact.
Triage speed
- Apple
- Historically the slower of the two — multi-month waits on complex chains are common, and payment often follows the patch release.
- Google
- Faster first response, typically days for a triage decision, with a published panel cadence for reward amounts.
Duplicates
- Apple
- First valid report is paid; later duplicates receive nothing.
- Google
- First valid report is paid, though Google credits duplicate reporters publicly.
Best suited to
- Apple
- Specialists in memory safety and kernel work who can invest months in one target.
- Google
- Web and mobile researchers who want volume, faster feedback, and a wider asset list.
Payout figures reflect each vendor's published reward tables and change over time — check the official program pages before committing to a target.
How to choose between them
Pick Apple if you already work in memory safety, kernel internals, or sandbox escapes and can spend months on one chain without income. The ceiling is the highest in the industry and the competition is thin because the barrier is real.
Pick Google if you want feedback loops measured in days. The scope spans every Google web property plus Android, Chrome, Cloud, and open source, so there is always another asset to test, and the triage cadence means you learn quickly whether your approach works.
Both share the same structural problem: you do the work first, and only after submission does anyone tell you whether it counted. Duplicates pay nothing, out-of-scope findings pay nothing, and neither clock is yours to control.
Common questions
- Which bug bounty pays more, Apple or Google?
- Apple's ceiling is higher — its top award reaches $2,000,000 for a zero-click remote chain, against roughly $151,515 for Google's top Android chain. In practice most researchers earn more per year from Google because its scope is far wider and its triage is faster, so more reports convert.
- Which program is easier to get started with?
- Google's. The Vulnerability Reward Program covers hundreds of web properties where a single well-documented flaw can qualify, while Apple's program is concentrated on operating system internals that require a working exploit on current software.
- How long does payment take?
- Google usually triages within days and pays after its reward panel meets. Apple's payouts commonly follow the patch release, which can be several months after the report for complex issues.
- Do either of them pay for duplicate reports?
- No. Both pay the first valid report only. This is the core economic risk of classic bug bounty work: your time is spent before anyone confirms the finding is yours.
- What is the alternative to waiting for a bounty decision?
- Escrow-funded coding bounties invert the model. The money is deposited before the task is listed and the deadline is fixed, so you know the reward exists and when it resolves before you start writing.
A funded alternative
CodeMarket bounties are funded into escrow before the listing goes live, so the reward is verifiably there before you start. The listing shows exactly what lands in your wallet, your source code stays private until the reward is released, and if the deadline passes without an accepted solution everything is refunded automatically.