Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Management & Strategy

Google Paid Out $9 Million in Bug Bounties Since 2010

Google has awarded researchers more than $9 million since the launch of its bug bounty program in 2010, including over $3 million paid out last year.

Google has awarded researchers more than $9 million since the launch of its bug bounty program in 2010, including over $3 million paid out last year.

According to the company, more than 1,000 payments were made last year to roughly 350 researchers from 59 countries. The biggest single reward was $100,000 and over $130,000 were donated by the search giant to charity.

Google also said it had paid out nearly $1 million each for vulnerabilities affecting the Android operating system and the Chrome web browser. In June, one year after the launch of its Android bug bounty program, the company decided to increase rewards for Android flaws.

In 2016, the company opened its Chrome Fuzzer Program to the public. The program allows experts to run fuzzers at large scale and they receive rewards automatically.

Google also highlighted the stories of an expert who donated his rewards to a Special Olympics team in the U.S., and an Indian researcher who funds his startup with bug bounty rewards.

The “2016 year in review” report also shows a proof-of-concept (PoC) video submitted by Frans Rosén, in which the researcher’s actions are synchronized to the background music. The video demonstrates a cross-site scripting (XSS) vulnerability in the payments.google.com domain.

Advertisement. Scroll to continue reading.

Google has been involved in third-party hacking competitions such as Pwn2Own and Pwnfest, but it also runs its own events. A contest that will run until March 14, named The Project Zero Prize, offers significant rewards to anyone who can achieve remote code execution on Nexus 6P and Nexus 5X smartphones by knowing only their email address and phone number.

Related: Google Pays $25,000 Reward for Critical Chrome Flaw

Related: Chrome 56 Patches 51 Vulnerabilities

Related: Google Patches 74 Vulnerabilities in Android

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Jazz has named Sean Robinson, Rickie Goyal, Danielle Guetta, Shani Nago, and Lior Magram as VPs and Michael Calev as COO.

AJ Shipley has been appointed Chief Product Officer at CrowdStrike.

Brinqa has named Ron Dovich as Chief AI and Automation Officer, David Allen as CTO, Steve Biagioni as CFO, and James Walta as VP of Product.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.