> which allows an attacker to confirm whether a visitor to a web page is logged in to any one of a list of specific Google accounts
I actually reported a similar problem to Google that would allow you to do the same thing back in 2013 (and like you, I used the load and onerror methods for detection). I didn't get a reward either :/.
However, Facebook paid me $1,000 for finding this problem for a particular area of their website (http://patorjk.com/blog/2013/03/01/facebook-user-identificat...). So I wouldn't write off this kind of security issue. It seems to depend on who's giving out the bounty.