Google paid $10 million in bug bounty rewards last year
ID: fad36d4d-7bb1-500a-ac5d-854500aa83bc
STIX ID: report--fad36d4d-7bb1-500a-ac5d-854500aa83bc
Feed Name: Bleeping Computer
Google’s 2023 Vulnerability Reward Program awarded $10M to 632 researchers across 68 countries, with major payouts in Android ($3.4M+) and Chrome (359 reports totaling $2.1M), plus additional awards for findings in Wear OS/Android Automotive OS and Nest/Fitbit/Wearables. The program raised caps for critical Android bugs, temporarily tripled rewards for Chrome sandbox escape chains, expanded recognition for older V8 issues, and introduced MiraclePtr in Chrome M116 along with a separate reward class for bypasses. Initiatives included Bonus Awards, exploit reward expansion (v8CTF), the Mobile VRP for first-party Android apps, the Bughunters blog, the ESCAL8 conference, and bugSWAT payouts for generative AI testing (e.g., Bard).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
