Google paid almost $12 million in bug bounty rewards to 660 security researchers who reported security bugs through the company's Vulnerability Reward Program (VRP) in 2024. Among last year's highlights, the company revamped the VRP's reward structure, bumping rewards up to a maximum of $151,515, while its Mobile VRP now offers up to $300,000 for critical vulnerabilities in top-tier apps (with a maximum reward reaching $450,000 for exceptional quality reports). The Cloud VRP increased the top-tier reward amounts by up to five times in July, while Chrome security bug rewards now exceed $250,000. Last year, Google more than doubled rewards for MiraclePtr bypasses to $250,128 from $100,115 when the MiraclePtr Bypass Reward was launched. It also launched kvmCTF, a new VRP unveiled in October 2023, aiming to improve the security of the Kernel-based Virtual Machine (KVM) hypervisor, that offers $250,000 bounties for full VM escape exploits. The company says it awarded $65 million in bug bounties since its first vulnerability reward program went live in 2010, while the highest reward paid last year was over $110,000. In 2024, Google awarded $3.4 million to 137 Chrome VRP researchers after analyzing 137 reports of valid Chrome security bugs. The highest bug bounty of 2024 was $100,115 for the report of a MiraclePtr Bypass after MiraclePtr was initially enabled across most platforms in Chrome M115 in 2023. The company also paid over $3.3 million to researchers who reported security ...
Google paid $12 million in bug bounties last year to security researchers
BleepingComputer
·Sergiu Gatlan
·Published Mar 10, 2025
·Updated
Affected Software
5 affected components
Google Android
Google Chrome
Google Kernel-based Virtual Machine (KVM)
Google Chrome
Google KVM
Frequently Asked Questions
1
What is the total amount Google paid in bug bounties last year?
Google paid almost $12 million in bug bounty rewards to security researchers in 2024.
2
How many security researchers participated in Google's Vulnerability Reward Program?
A total of 660 security researchers reported security bugs through Google's Vulnerability Reward Program.
3
What software products are highlighted as affected by reported security bugs?
The affected software includes Google Android, Google Chrome, and Google KVM.
4
What was the purpose of Google's Vulnerability Reward Program?
The program aims to incentivize security researchers to identify and report vulnerabilities in Google's products.
5
What highlights were mentioned regarding Google's bug bounty program in the article?
The article mentions that Google revamped aspects of the Vulnerability Reward Program in 2024.