Google has awarded researchers more than $9 million since the launch of its bug bounty program in 2010, including over $3 million paid out last year.
According to the company, more than 1,000 payments were made last year to roughly 350 researchers from 59 countries. The biggest single reward was $100,000 and over $130,000 were donated by the search giant to charity.
Google also said it had paid out nearly $1 million each for vulnerabilities affecting the Android operating system and the Chrome web browser. In June, one year after the launch of its Android bug bounty program, the company decided to increase rewards for Android flaws.
In 2016, the company opened its Chrome Fuzzer Program to the public. The program allows experts to run fuzzers at large scale and they receive rewards automatically.
Google also highlighted the stories of an expert who donated his rewards to a Special Olympics team in the U.S., and an Indian researcher who funds his startup with bug bounty rewards.
The “2016 year in review” report also shows a proof-of-concept (PoC) video submitted by Frans Rosén, in which the researcher’s actions are synchronized to the background music. The video demonstrates a cross-site scripting (XSS) vulnerability in the payments.google.com domain.
Google has been involved in third-party hacking competitions such as Pwn2Own and Pwnfest, but it also runs its own events. A contest that will run until March 14, named The Project Zero Prize, offers significant rewards to anyone who can achieve remote code execution on Nexus 6P and Nexus 5X smartphones by knowing only their email address and phone number.
Related: Google Pays $25,000 Reward for Critical Chrome Flaw
Related: Chrome 56 Patches 51 Vulnerabilities
Related: Google Patches 74 Vulnerabilities in Android

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
More from Eduard Kovacs
- In Other News: AI Regulation, Layoffs, US Aerospace Attacks, Post-Quantum Encryption
- Evidence Suggests Ransomware Group Knew About MOVEit Zero-Day Since 2021
- Vulnerabilities in Honda eCommerce Platform Exposed Customer, Dealer Data
- Barracuda Urges Customers to Replace Hacked Email Security Appliances
- Google Patches Third Chrome Zero-Day of 2023
- ChatGPT Hallucinations Can Be Exploited to Distribute Malicious Code Packages
- AntChain, Intel Create New Privacy-Preserving Computing Platform for AI Training
- Several Major Organizations Confirm Being Impacted by MOVEit Attack
Latest News
- In Other News: AI Regulation, Layoffs, US Aerospace Attacks, Post-Quantum Encryption
- Blackpoint Raises $190 Million to Help MSPs Combat Cyber Threats
- Google Introduces SAIF, a Framework for Secure AI Development and Use
- ‘Asylum Ambuscade’ Group Hit Thousands in Cybercrime, Espionage Campaigns
- Evidence Suggests Ransomware Group Knew About MOVEit Zero-Day Since 2021
- SaaS Ransomware Attack Hit Sharepoint Online Without Using a Compromised Endpoint
- Google Cloud Now Offering $1 Million Cryptomining Protection
- Democrats and Republicans Are Skeptical of US Spying Practices, an AP-NORC Poll Finds
