logo

Virtual Escape; Real Reward: Introducing Google’s kvmCTF

ID: d65a1b85-2c83-5275-93fb-0ed00c0c48b5

STIX ID: report--d65a1b85-2c83-5275-93fb-0ed00c0c48b5

Feed Name: Google Online Security Blog

Date Published: 2024-06-27

Date Updated: 2026-04-27

Author: Kimberly Samra

...
...

Google announced kvmCTF, a vulnerability reward program for zero-day flaws in the KVM hypervisor, offering a controlled lab where participants attempt guest-to-host exploits to capture flags. Rewards range from $10,000 to $250,000 based on impact (including relative/absolute memory read/write, DoS, and full VM escape), with optional KASAN-enabled hosts to validate certain tiers. Participants reserve time slots, follow program rules for access and reporting, and disclose zero-days to Google only after upstream patches are released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.