Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In an August 2017 report, Ars Technica described Zerodium offering as much as $1.5 million for a fully functional iOS remote jailbreak that required no user interaction. The reported offer was $1 million when interaction was required. Zerodium also listed payments of up to $500,000 for working attacks against major encrypted-messaging apps. These were reported 2017 offer amounts, not a current Zerodium price list.

What Zerodium reportedly offered in 2017

The figures were tied to the target, the capability of the exploit and whether the victim had to do anything. Ars Technica reported the following mobile categories:

Target or capability Reported offer Important qualification
iOS remote jailbreak $1.5 million Remote, fully functional attack requiring no user interaction
iOS remote jailbreak $1 million Fully functional attack requiring user interaction
Signal, WhatsApp, iMessage, Viber, WeChat, Telegram and default mobile email apps $500,000 Fully functional exploits targeting the named services or apps
Advanced mobile baseband exploit $150,000 Mobile category reported by Ars Technica
Malicious-code-executing media file or document $150,000 File or document had to execute malicious code
Certain file-based security bypasses and Wi-Fi exploits $100,000 Applies to the categories described in the 2017 report

These amounts were company offer figures reported by a news outlet, not independently measured market averages. The available report does not establish that any amount remains available today.

Why the iOS figure was higher

The top price reflected a particularly demanding combination: a remote attack, no required victim action and a jailbreak that gave the attacker broad control. Requiring the victim to tap a link, open a file or perform another action reduced the reported offer to $1 million. In other words, the announcement priced reliability and access, not merely the existence of a bug.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the $500,000 messaging-app category meant

The $500,000 category covered fully functional attacks against Signal, WhatsApp, iMessage, Viber, WeChat, Telegram and default mobile email applications. The wording matters: the reported amount was for a working attack chain against the named targets, rather than a theoretical weakness or an isolated crash.

A vulnerability in an app, an exploit that reaches code execution and a complete attack that works reliably are different deliverables. Zerodium’s reported schedule valued the last of these most highly.

Exploit broker offers versus bug bounties

Comparing the headline amounts with ordinary bug-bounty rewards can be misleading. The relevant differences are:

  • Deliverable: Zerodium’s reported prices were for fully functional attacks; many public bug-bounty programs accept proof-of-concept submissions or vulnerability reports that do not provide a complete compromise.
  • Target and platform: A high-impact iOS chain or an attack against a named messaging app is not equivalent to a lower-impact bug in a web service or unrelated platform.
  • User interaction: The 2017 iOS figures changed by $500,000 depending on whether the victim had to interact.
  • Downstream visibility: A bug-bounty researcher normally reports to the affected vendor. A broker seller may have less visibility into who ultimately receives the exploit and how it is used.

Therefore, the dollar amounts should not be treated as a universal exchange rate for security bugs or as evidence that every zero-day is worth millions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The transparency concern

Ars Technica reported that Zerodium said purchased exploits were restricted to a small set of vetted organizations. The same report noted that the company had not disclosed its customer list, so readers could not independently verify those assurances from the information available at the time.

“The other big drawback to submitting to Zerodium: exploit developers don’t know where their creations wind up or how, or against whom, they’re used.”

— Dan Goodin, Ars Technica

That uncertainty is central to the trade-off. A researcher considering a broker is weighing a potentially larger payment against reduced control over downstream use, disclosure and remediation. The report does not identify the buyers of the exploits described in the announcement.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to read the announcement today

It is a historical pricing snapshot

The announcement was reported in 2017. It shows what Zerodium publicly offered in that period and how the broker differentiated exploit quality; it does not document Zerodium’s current rates, eligibility rules, payment process or customer policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
  • Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
  • Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
  • Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)

It describes offers, not guaranteed payouts

An offer ceiling is not a promise that every submission would receive the maximum amount. Acceptance would depend on factors such as the exact target, exploit reliability and whether the submission met the stated capability.

It illustrates why exploit quality matters

The progression from $100,000 and $150,000 categories to $500,000 app attacks and the $1 million-to-$1.5 million iOS jailbreak range demonstrates how access, reliability, scope and user interaction affected the reported valuation.

What readers should take away

  • The highest figure reported was $1.5 million for a no-interaction, remote iOS jailbreak.
  • A user-interaction requirement reduced the reported iOS figure to $1 million.
  • Fully functional attacks against the named messaging and mobile email targets were listed at $500,000.
  • Other mobile categories were listed at $150,000 or $100,000 depending on capability.
  • All amounts belong to the 2017 report and should not be quoted as current Zerodium pricing.
  • The report raised an unresolved visibility issue because Zerodium’s customers were not publicly identified.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.