In temporary: Google has introduced that it awarded a large $10 million last yr in bug bounty rewards, the second-largest quantity the program has ever paid out. The highest single award in 2023 was a powerful $113,337.
Google says that the $10 million it paid out by way of its Vulnerability Reward Program went to 632 researchers from 68 nations who found and reported vulnerabilities in the firm’s merchandise.
Last yr’s whole was barely decrease than the document $12 million Google paid out in bug bounty rewards throughout 2022, however it’s nonetheless the second-largest quantity ever. Since the program launched in 2010, it has earned researchers a complete of $59 million.
For its Android OS, Google handed over $3.4 million in rewards to researchers who uncovered vulnerabilities in the cell working system. Google additionally elevated its most reward quantity for Android-related discoveries to $15,000, serving to incentivize reporting.
Last yr noticed Wear OS added to the bug bounty program in the hope that it’s going to encourage extra researchers to search for vulnerabilities in wearable know-how that might put customers in danger.
Google highlighted some safety conferences the place a number of points have been uncovered. It hosted a reside hacking occasion for Wear OS and Android Automotive OS at the ESCAL8 convention, which noticed researchers awarded $70,000 for locating over 20 important vulnerabilities. It additionally spotlighted the hardwear.io safety conferences, the place {hardware} safety researchers uncovered over 50 vulnerabilities in Nest, Fitbit, and Wearables, incomes them a complete of $116,000 last yr.
Google added generative AI to its Vulnerability Reward Program in 2023. It ran a bugSWAT live-hacking occasion concentrating on LLM merchandise that resulted in 35 studies and greater than $87,000 being paid out. It additionally uncovered points like Hacking Google Bard – From Prompt Injection to Data Exfiltration and We Hacked Google A.I. for $50,000.
Elsewhere, one Chrome researcher grabbed a $30,000 reward for reporting a V8 JIT optimization bug that had been in the browser since at the very least M91, which acquired a steady launch in May 2021.



