In an August 2017 report, Ars Technica described Zerodium offering as much as $1.5 million for a fully functional iOS remote jailbreak that required no user interaction. The reported offer was $1 million when interaction was required. Zerodium also listed payments of up to $500,000 for working attacks against major encrypted-messaging apps. These were reported 2017 offer amounts, not a current Zerodium price list.
What Zerodium reportedly offered in 2017
The figures were tied to the target, the capability of the exploit and whether the victim had to do anything. Ars Technica reported the following mobile categories:
| Target or capability | Reported offer | Important qualification |
|---|---|---|
| iOS remote jailbreak | $1.5 million | Remote, fully functional attack requiring no user interaction |
| iOS remote jailbreak | $1 million | Fully functional attack requiring user interaction |
| Signal, WhatsApp, iMessage, Viber, WeChat, Telegram and default mobile email apps | $500,000 | Fully functional exploits targeting the named services or apps |
| Advanced mobile baseband exploit | $150,000 | Mobile category reported by Ars Technica |
| Malicious-code-executing media file or document | $150,000 | File or document had to execute malicious code |
| Certain file-based security bypasses and Wi-Fi exploits | $100,000 | Applies to the categories described in the 2017 report |
These amounts were company offer figures reported by a news outlet, not independently measured market averages. The available report does not establish that any amount remains available today.
Why the iOS figure was higher
The top price reflected a particularly demanding combination: a remote attack, no required victim action and a jailbreak that gave the attacker broad control. Requiring the victim to tap a link, open a file or perform another action reduced the reported offer to $1 million. In other words, the announcement priced reliability and access, not merely the existence of a bug.
#1 Best Overall
What the $500,000 messaging-app category meant
The $500,000 category covered fully functional attacks against Signal, WhatsApp, iMessage, Viber, WeChat, Telegram and default mobile email applications. The wording matters: the reported amount was for a working attack chain against the named targets, rather than a theoretical weakness or an isolated crash.
A vulnerability in an app, an exploit that reaches code execution and a complete attack that works reliably are different deliverables. Zerodium’s reported schedule valued the last of these most highly.
Rank #2
Exploit broker offers versus bug bounties
Comparing the headline amounts with ordinary bug-bounty rewards can be misleading. The relevant differences are:
- Deliverable: Zerodium’s reported prices were for fully functional attacks; many public bug-bounty programs accept proof-of-concept submissions or vulnerability reports that do not provide a complete compromise.
- Target and platform: A high-impact iOS chain or an attack against a named messaging app is not equivalent to a lower-impact bug in a web service or unrelated platform.
- User interaction: The 2017 iOS figures changed by $500,000 depending on whether the victim had to interact.
- Downstream visibility: A bug-bounty researcher normally reports to the affected vendor. A broker seller may have less visibility into who ultimately receives the exploit and how it is used.
Therefore, the dollar amounts should not be treated as a universal exchange rate for security bugs or as evidence that every zero-day is worth millions.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Rank #3
The transparency concern
Ars Technica reported that Zerodium said purchased exploits were restricted to a small set of vetted organizations. The same report noted that the company had not disclosed its customer list, so readers could not independently verify those assurances from the information available at the time.
“The other big drawback to submitting to Zerodium: exploit developers don’t know where their creations wind up or how, or against whom, they’re used.”
Rank #4
— Dan Goodin, Ars Technica
That uncertainty is central to the trade-off. A researcher considering a broker is weighing a potentially larger payment against reduced control over downstream use, disclosure and remediation. The report does not identify the buyers of the exploits described in the announcement.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to read the announcement today
It is a historical pricing snapshot
The announcement was reported in 2017. It shows what Zerodium publicly offered in that period and how the broker differentiated exploit quality; it does not document Zerodium’s current rates, eligibility rules, payment process or customer policy.
Best Value
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
- Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
- Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
- Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
It describes offers, not guaranteed payouts
An offer ceiling is not a promise that every submission would receive the maximum amount. Acceptance would depend on factors such as the exact target, exploit reliability and whether the submission met the stated capability.
It illustrates why exploit quality matters
The progression from $100,000 and $150,000 categories to $500,000 app attacks and the $1 million-to-$1.5 million iOS jailbreak range demonstrates how access, reliability, scope and user interaction affected the reported valuation.
Quick Recap
What readers should take away
- The highest figure reported was $1.5 million for a no-interaction, remote iOS jailbreak.
- A user-interaction requirement reduced the reported iOS figure to $1 million.
- Fully functional attacks against the named messaging and mobile email targets were listed at $500,000.
- Other mobile categories were listed at $150,000 or $100,000 depending on capability.
- All amounts belong to the 2017 report and should not be quoted as current Zerodium pricing.
- The report raised an unresolved visibility issue because Zerodium’s customers were not publicly identified.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

