The math that makes a $1,000 bug bounty feel like a test we're failing
A new CVE-2026-85046 is actively being exploited in the wild — a sandbox escape and remote code execution that affects every Chromium-based browser. The vulnerability was responsibly disclosed to Google, which fixed it and paid the researcher a $1,000 bounty. As one Hacker News commenter pointed out, the market value of a zero-day sandbox escape is orders of magnitude higher. A sophisticated exploit like this — one that Kaspersky described as making the security boundary “simply not exist” — isn’t something you find every day. The gap between what the researcher received and what the bug is worth to state actors or cybercriminal groups is not just a pricing problem; it’s a structural failure in how we value public good.
The Qur’an reminds us that we are always being tested, and that the tests themselves contain lessons. The test here is not just for the researcher who chose to disclose rather than sell, but for the platform that determines the reward. A $1,000 payment for a vulnerability that could affect billions of users and countless systems sends a troubling signal. It suggests that the current bounty system is calibrated more to cost management than to the actual risk mitigated. When a researcher is effectively penalised for acting ethically — walking away from a potential six-figure payout to protect users — the system is not working as intended.
Google’s bounty programme is one of the most generous in the industry, and the company does pay significantly more for critical bugs in some cases. But the inconsistency matters. If a sandbox RCE in the world’s most widely used browser engine is worth only $1,000, what does that say about how we value the security of the open web? The researcher’s decision to report responsibly should be celebrated, and the reward should reflect the magnitude of the protection provided. The lesson here is that we need to rethink the economics of vulnerability disclosure — not to enrich researchers, but to ensure that the incentives point toward safety rather than the black market.
A better approach would be to tie bounties to the severity of the exploit’s impact, the difficulty of discovery, and the speed of the fix — essentially, a sliding scale that rewards the kind of work that keeps the internet from crumbling. This is a test of institutional integrity. And the grade, so far, is incomplete.
Comments
Login to add a comment
No comments yet. Be the first to comment!
