reported a chrome fullchain (web -> shell) on pixel 10 to google. got a 9.6 cve (cve-2026-87464) and a fix in chrome.
now they bend the rules and refuse to pay the fullchain bonus bc one of the vulns in the chain was an unpatched nday. total payout: $2.5k. despite cve + shell :|
https://x.com/1lexxi/status/2102771891630928223