Article Details
Scrape Timestamp (UTC): 2025-03-10 15:29:01.751
Original Article Text
Click to Toggle View
Google paid $12 million in bug bounties last year to security researchers. Google paid almost $12 million in bug bounty rewards to 660 security researchers who reported security bugs through the company's Vulnerability Reward Program (VRP) in 2024. Among last year's highlights, the company revamped the VRP's reward structure, bumping rewards up to a maximum of $151,515, while its Mobile VRP now offers up to $300,000 for critical vulnerabilities in top-tier apps (with a maximum reward reaching $450,000 for exceptional quality reports). The Cloud VRP increased the top-tier reward amounts by up to five times in July, while Chrome security bug rewards now exceed $250,000. Last year, Google more than doubled rewards for MiraclePtr bypasses to $250,128 from $100,115 when the MiraclePtr Bypass Reward was launched. It also launched kvmCTF, a new VRP unveiled in October 2023, aiming to improve the security of the Kernel-based Virtual Machine (KVM) hypervisor, that offers $250,000 bounties for full VM escape exploits. The company says it awarded $65 million in bug bounties since its first vulnerability reward program went live in 2010, while the highest reward paid last year was over $110,000. In 2024, Google awarded $3.4 million to 137 Chrome VRP researchers after analyzing 137 reports of valid Chrome security bugs. The highest bug bounty of 2024 was $100,115 for the report of a MiraclePtr Bypass after MiraclePtr was initially enabled across most platforms in Chrome M115 in 2023. The company also paid over $3.3 million to researchers who reported security bugs through the company's Android and Google Devices Security Reward Program and the Google Mobile Vulnerability Reward Program. "In 2025, we will be celebrating 15 years of VRP at Google, during which we have remained fully committed to fostering collaboration, innovation, and transparency with the security community, and will continue to do so in the future," Google said. "Our goal remains to stay ahead of emerging threats, adapt to evolving technologies, and continue to strengthen the security posture of Google's products and services." One year earlier, in 2023, Google awarded $10 million to 632 researchers for finding and responsibly reporting security flaws in its products and services. Top 10 MITRE ATT&CK© Techniques Behind 93% of Attacks Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.
Daily Brief Summary
Google paid nearly $12 million in bug bounties to 660 researchers in 2024 under its Vulnerability Reward Program.
Reward structures were restructured, with significant increases: Critical vulnerabilities in mobile apps now fetch up to $450,000.
The Cloud VRP saw a five-fold increase in top reward amounts, emphasizing cloud security enhancement.
Google introduced kvmCTF to fortify the security of Kernel-based Virtual Machines, offering $250,000 for major exploits.
A total of $65 million has been awarded in bounties since the inception of Google's vulnerability reward programs in 2010.
In 2024 alone, $3.4 million was paid out to Chrome researchers, highlighting their contribution in catching security bugs.
The highest single reward in 2024 was $110,000, showing Google's commitment to compensating top-quality security research.
Google plans to continue expanding and improving its bug bounty programs, underscoring a lasting commitment to cybersecurity innovation and collaboration.