logo

Google now pays $250,000 for KVM zero-day vulnerabilities

ID: e8493088-bdf3-58f8-a6f8-6c38f2f340a8

STIX ID: report--e8493088-bdf3-58f8-a6f8-6c38f2f340a8

Feed Name: Bleeping Computer

Date Published: 2024-07-02

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Google launched kvmCTF, a new vulnerability reward program targeting zero-day, guest-to-host exploits in the KVM hypervisor, offering rewards up to $250,000 for full VM escapes. The program provides a controlled lab environment for researchers to capture flags, focuses strictly on VM-reachable KVM bugs (excluding QEMU/host-to-KVM issues), and maps KASAN violations to reward tiers. Vulnerability details are shared with Google only after upstream patches are released, and participants must follow published rules for reservations, exploitation, and reporting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.