Reward ceilings are signals, not promises.

Many programs advertise a maximum reward for exceptional severity, full exploit chains, or unusual impact. Actual payouts vary by scope, report quality, affected product, reproducibility, and prior disclosure status. Always verify live terms directly on the official program page before investing serious research time.

Checked April 26, 2026Official sources onlyReward ceilings can change

Major public programs worth tracking.

Mobile / platformApple

Apple Security Bounty

Up to $2,000,000

Apple continues to set one of the highest public ceiling rewards, especially for severe lock-screen bypass and zero-click style impact on modern devices.

Apple Security Bounty

Web / platformMeta

Meta Bug Bounty

Up to $300,000

Meta remains one of the biggest-name public programs and explicitly advertises six-figure payouts for exceptional impact.

Meta Bug Bounty

BrowserGoogle

Google Chrome VRP

Up to $250,000+

Google's Chrome VRP remains one of the most prestigious browser programs, with very high rewards for top-tier exploit chains and exceptional research quality.

Google VRP and 2025 rewards review

Mobile / AndroidGoogle

Google Mobile VRP

Up to $300,000

Google publicly notes very high Android and mobile-class rewards, making it one of the strongest programs for mobile exploit research.

Google VRP and 2024 rewards review

Cloud / enterpriseMicrosoft

Microsoft Bug Bounty Programs

Up to $40,000 program-specific bounties

Microsoft's bug bounty portfolio spans cloud, identity, AI, and enterprise products, and its separate research events can make the total opportunity much larger.

Microsoft Bug Bounty Program

AI platformOpenAI

OpenAI Bug Bounty

Up to $100,000

OpenAI's program is highly relevant for researchers focused on AI product security, account issues, data exposure, and platform trust.

OpenAI Bug Bounty Program