> Remember how revolutionary pwn2own was? "Wow, find a vulnerability and win $1000!". These days vulnerabilities of that magnitude are worth way more money, because of how secure the browser environment has become.
Theses amounts were low because there was no interest in rewarding white hat hackers sadly. Bug bounties at the time were extremely rare. It wasn't lower because it was easier (though it may have been easier, not arguing it wasn't, just that the amounts are not evidence of it).
> ($100k-$1M on the black market as I understand it.)
On the "white" market you means. Zerodium is paying theses amounts. I don't feel like it would be higher in the black market than what they are offering, but could be.
Speaking of which, in 2020 Zerodium stopped accepting "Apple iOS LPE, Safari RCE, or sandbox escapes" for a few months because there was too many of them... still no "Thought on iOS" yet... It's not like it's even a new thing, I remember a long time ago when you could jailbreak your iPhone using a website directly.
Didn't even need to go far either... check CVE-2022-22620, only a month ago.