Skip to main content

Google will give you up to $200K if you can hack the newest version of Android

google antitrust eu extension version 1475495165 androidn head
Image used with permission by copyright holder
Think you’ve got the hacking chops to breach a flagship Android phone? Google’s willing to pay you to prove it. On Wednesday, the Mountain View, California-based company announced Project Zero, a contest that asks enterprising hackers to demonstrate flaws in the company’s smartphone operating system in exchange for cold, hard cash.

“Despite the existence of vulnerability rewards programs at Google and other companies, many unique, high-quality security bugs have been discovered as a result of hacking contests,” Google’s Natalie Silvanovich wrote in a blog post. “The goal of this contest is to find a vulnerability or bug chain that achieves remote code execution on multiple Android devices knowing only the devices’ phone number and email address.”

Recommended Videos

Here’s how it works: Hackers who uncover a serious security bug, exploit, or flaw in Android are encouraged to publish them on the Android issue tracker, a public forum devoted to documenting Android issues, from visual glitches to wonky Wi-Fi. Posts will have to be detailed — contest participants must share a “full description” of how the exploit works with the expectation that, if verified independently, they’ll be published on a public Google blog. They’ll have to work on Google’s branded Nexus devices, the Huawei-made Nexus 6P and LG’s Nexus 5X, plus any devices running an up-to-date build of Android 7.0 Nougat. And the more, the better — reported bugs can contribute to a larger Project Zero submission at any time during the contest’s six-month period, Google said.

Please enable Javascript to view this content

The prizes ain’t half bad. The winner of the contest takes home $200,000, while the runner-up will net $100,000. An undisclosed number of entries will be receive a consolatory prize of $50,000 as well. And there’s no way to lose: Google said bugs that aren’t submitted during the entry period may be considered for other contests like Android Security Rewards, as well as future, as-yet-unannounced promotions.

Project Zero’s impetus, Google said, was discovering bugs that would otherwise go unreported. Another motivation? Developing fixes quickly, and in some cases pre-emptively. “Our main motivation is to gain information about how these bugs and exploits work,” Silvanovich wrote.” There are often rumors of remote Android exploits, but it’s fairly rare to see one in action. We’re hoping this contest will improve the public body of knowledge on these types of exploits.”

More broadly, Google is hoping to dissuade unscrupulous types who otherwise might be inclined to sell exploits to the highest bidder. McAfee’s Center for Strategic and International Studies estimated that the cost of cybercrime is somewhere around $160 billion a year. And as use of mobile devices has climbed to unprecedented levels, the price of so-called zero-day bugs — exploits deriving from a previously unknown vulnerability — on internet black markets has mirrored that growth. A zero-day flaw in the latest version of iOS, for example, can sell for as much as $250,000, according to Wired, and some foreign governments have reportedly paid nearly half a million dollars for comparable bugs.

“We’re hoping to get dangerous bugs fixed so they don’t impact users,” Silvanovich said. “We’re [hoping] that this contest will give us another data point on the availability of these types of exploits.”

Project Zero began Wednesday.

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
The OnePlus 13 is coming on January 7 — along with a surprise
The OnePlus logo on the back of the OnePlus Open Apex Edition.

It's official: the OnePlus 13 will launch on January 7, 2025. Preempting the anticipated event by several weeks, OnePlus has officially confirmed the date we’ll see its next major smartphone release outside of China. Additionally, it has revealed some key features and news of a surprise new launch to go along with the phone.

OnePlus will release the OnePlus 13 in three different colors — Black Eclipse, Arctic Dawn, and Midnight Ocean. It’s the latter that is likely to be the model to have, as it is wrapped in a material called micro-fiber vegan leather, which is apparently corrosion and scratch-resistant but still luxurious to the touch. For the Arctic Dawn phone, the glass will have a special coating to give it a silky-smooth finish. It’s likely these are the same colors offered in China, where the phone has already been announced, just with different names.

Read more
I’m really worried about the future of smart glasses
The front of the Ray-Ban Meta smart glasses.

The Ray-Ban Meta smart glasses are among the most interesting, unexpectedly fun, and surprisingly useful wearables I’ve used in 2024. However, as we go into 2025, I’m getting worried about the smart glasses situation.

This isn’t the first time I’ve felt like we’re on the cusp of a new wave of cool smart eyewear products, only to be very disappointed by what came next.
Why the Ray-Ban Meta are so good

Read more
We need to talk about this fantastic, industry-leading Motorola collab
A person holding the Motorola Edge 50 Neo.

We are accustomed to tech brands partnering with adjacent brands, whether it’s OnePlus with Hasselblad or Honor and Huawei with Porsche Design, and often — such as with Xiaomi and Leica — singing the praises of the resulting collaborations. But not enough has been said about Motorola’s now established partnership with color experts Pantone.

It was when the recently released Motorola Edge 50 Neo arrived for me to try out that I finally understood how impactful the collaboration has become. Why? It manages to make even ordinary colors look fantastic.
Boring gray?

Read more