https://www.bleepingcomputer.com/news/google/google-paid-10-million-in-bug-bounty-rewards-last-year/ BleepingComputer.com logo * * * * [ ] [Login] [Sign up] * * * * [ ] [Login] [Sign up] * News + Featured + Latest + Over 15,000 hacked Roku accounts sold for 50C/ each to buy hardware Over 15,000 hacked Roku accounts sold for 50C/ each to buy hardware + QNAP warns of critical auth bypass flaw in its NAS devices QNAP warns of critical auth bypass flaw in its NAS devices + Fake Leather wallet app on Apple App Store is a crypto drainer Fake Leather wallet app on Apple App Store is a crypto drainer + YouTube stops recommending videos when signed out of Google YouTube stops recommending videos when signed out of Google + Windows KB5035849 update failing to install with 0xd000034 errors Windows KB5035849 update failing to install with 0xd000034 errors + Stanford: Data of 27,000 people stolen in September ransomware attack Stanford: Data of 27,000 people stolen in September ransomware attack + Acer confirms Philippines employee data leaked on hacking forum Acer confirms Philippines employee data leaked on hacking forum + Get Microsoft Office for $200 off with this StackCommerce deal Get Microsoft Office for $200 off with this StackCommerce deal * Tutorials + Latest + Popular + How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 + How to use the Windows Registry Editor How to use the Windows Registry Editor + How to backup and restore the Windows Registry How to backup and restore the Windows Registry + How to open a Windows 11 Command Prompt as Administrator How to open a Windows 11 Command Prompt as Administrator + How to start Windows in Safe Mode How to start Windows in Safe Mode + How to remove a Trojan, Virus, Worm, or other Malware How to remove a Trojan, Virus, Worm, or other Malware + How to show hidden files in Windows 7 How to show hidden files in Windows 7 + How to see hidden files in Windows How to see hidden files in Windows * Virus Removal Guides + Latest + Most Viewed + Ransomware + Remove the Theonlinesearch.com Search Redirect Remove the Theonlinesearch.com Search Redirect + Remove the Smartwebfinder.com Search Redirect Remove the Smartwebfinder.com Search Redirect + How to remove the PBlock+ adware browser extension How to remove the PBlock+ adware browser extension + Remove the Toksearches.xyz Search Redirect Remove the Toksearches.xyz Search Redirect + Remove Security Tool and SecurityTool (Uninstall Guide) Remove Security Tool and SecurityTool (Uninstall Guide) + How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo + How to remove Antivirus 2009 (Uninstall Instructions) How to remove Antivirus 2009 (Uninstall Instructions) + How to remove Google Redirects or the TDSS, TDL3, or Alureon rootkit using TDSSKiller How to remove Google Redirects or the TDSS, TDL3, or Alureon rootkit using TDSSKiller + Locky Ransomware Information, Help Guide, and FAQ Locky Ransomware Information, Help Guide, and FAQ + CryptoLocker Ransomware Information Guide and FAQ CryptoLocker Ransomware Information Guide and FAQ + CryptorBit and HowDecrypt Information Guide and FAQ CryptorBit and HowDecrypt Information Guide and FAQ + CryptoDefense and How_Decrypt Ransomware Information Guide and FAQ CryptoDefense and How_Decrypt Ransomware Information Guide and FAQ * Downloads + Latest + Most Downloaded + Qualys BrowserCheck Qualys BrowserCheck + STOPDecrypter STOPDecrypter + AuroraDecrypter AuroraDecrypter + FilesLockerDecrypter FilesLockerDecrypter + AdwCleaner AdwCleaner + ComboFix ComboFix + RKill RKill + Junkware Removal Tool Junkware Removal Tool * Deals + Categories + eLearning eLearning + IT Certification Courses IT Certification Courses + Gear & Gadgets Gear + Gadgets + Security Security * VPNs + Popular + Best VPNs Best VPNs + How to change IP address How to change IP address + Access the dark web safely Access the dark web safely + Best VPN for YouTube Best VPN for YouTube * Forums * More + Startup Database + Uninstall Database + Glossary + Chat on Discord + Send us a Tip! + Welcome Guide * Home * News * Google * Google paid $10 million in bug bounty rewards last year * * Google paid $10 million in bug bounty rewards last year By Bill Toulas * March 12, 2024 * 12:00 PM * 0 Google Google awarded $10 million to 632 researchers from 68 countries in 2023 for finding and responsibly reporting security flaws in the company's products and services. Though this is lower than the $12 million Google's Vulnerability Reward Program paid to researchers in 2022, the amount is still significant, showcasing a high level of community participation in Google's security efforts. Total amount paid each yearTotal amount paid to researchers each year (Google) The highest reward for a vulnerability report in 2023 was $113,337, while the total tally since the program's launch in 2010 has reached $59 million. Summary For Android, the world's most popular and widely used mobile operating system, the program awarded over $3.4 million. Google also increased the maximum reward amount for critical vulnerabilities concerning Android to $15,000, driving increased community reports. During security conferences like ESCAL8 and hardwea.io, Google awarded $70,000 for 20 critical discoveries in Wear OS and Android Automotive OS and another $116,000 for 50 reports concerning issues in Nest, Fitbit, and Wearables. Google's other big software project, the Chrome browser, was the subject of 359 security bug reports that paid out a total of $2.1 million. On June 1, 2023, the company announced it would triple bounty payments for sandbox escape chain exploits targeting Chrome until December 1, 2023. The program also increased rewards for bugs in older (before M105) versions of V8, Chrome's JavaScript engine, leading to significant discoveries and rewards like a $30,000 award for a long-existing (since M91) V8 JIT optimization bug. Another point highlighted in Google's post is the introduction of 'MiraclePtr' in Chrome M116, which protects against non-renderer Use-After-Free (UAF) vulnerabilities. Due to these flaws being deemed 'highly mitigated' after the introduction of MiraclePtr, Google introduced a separate class of rewards for bypassing the protection mechanism itself. Finally, the review also touches on the efforts in security generative AI products like Google Bard, with 35 researcher reports in a bugSWAT live-hacking event generating $87,000 in payouts. Apart from the rewards themselves, the bug bounty program had the following key developments and enhancements during 2023: * The introduction of the Bonus Awards program, offering extra rewards for specific targets. * Expansion of the exploit reward program to include Chrome and Cloud, highlighted by the launch of v8CTF, focusing on Chrome's V8 JavaScript engine. * The inauguration of the Mobile VRP for first-party Android applications. * Launch of the Bughunters blog to share insights and safety measures for the internet. * The hosting of the ESCAL8 security conference in Tokyo, featuring live hacking events, workshops, and talks. Those who wish to get involved in Google's bug bounty program can learn more about it through its Bug Hunters community. Related Articles: Google says spyware vendors behind most zero-days it discovers New Google Chrome feature blocks attacks against home networks Google teases a new modern look for sign-in pages, including Gmail Google tests blocking side-loaded Android apps with risky permissions Check if you're in Google Chrome's third-party cookie phaseout test * Android * Bug Bounty * Bug Bounty Program * Google * Google Chrome * Vulnerability * * * * * Bill Toulas Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks. * Previous Article * Next Article Post a Comment Community Rules You need to login in order to post a comment [Login] Not a member yet? Register Now You may also like: [INS::INS] Popular Stories * Roku Over 15,000 hacked Roku accounts sold for 50C/ each to buy hardware * WordPress Hackers exploit WordPress plugin flaw to infect 3,300 sites with malware Follow us: * * * * * Main Sections * News * VPN Buyer Guides * Downloads * Virus Removal Guides * Tutorials * Startup Database * Uninstall Database * Glossary Community * Forums * Forum Rules * Chat Useful Resources * Welcome Guide * Sitemap Company * About BleepingComputer * Contact Us * Send us a Tip! * Advertising * Write for BleepingComputer * Social & Feeds * Changelog Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2024 Bleeping Computer^(r) LLC - All Rights Reserved Login Username [ ] Password [ ] [*] Remember Me [ ] Sign in anonymously [Login] Sign in with Twitter button Sign in with Twitter --------------------------------------------------------------------- Not a member yet? Register Now Reporter Help us understand the problem. What is going on with this comment? * ( )Spam * ( )Abusive or Harmful * ( )Inappropriate content * ( )Strong language * ( )Other [ ] * [ ] Read our posting guidelinese to learn what content is prohibited. Submitting... SUBMIT