Vulnerabilities

Zoom Paid Out $3.9 Million in Bug Bounties in 2022

Zoom says it paid out $3.9 million in bug bounty rewards in 2022, with a total of over $7 million awarded to researchers since 2019.

Zoom says it paid out $3.9 million in bug bounty rewards in 2022, with a total of over $7 million awarded to researchers since 2019.

Video communications giant Zoom this week announced that in 2022 it paid out $3.9 million to security researchers who reported vulnerabilities as part of its bug bounty program.

Zoom launched a private bug bounty program on HackerOne in 2019 and has paid out over $7 million in bounty rewards to date. In 2021, the company paid roughly $1.8 million in bug bounty rewards.

Moving forth, the company is working on implementing a new vulnerability impact scoring system that it will use alongside the Common Vulnerability Scoring System (CVSS) to score reports.

The new Vulnerability Impact Scoring System (VISS) will rank vulnerability reports based on 13 different aspects of their impact on Zoom’s infrastructure and technology, as well as on customer data security.

“With the implementation of VISS, Bug Bounty can focus more on measuring responsibly demonstrated impact, rather than the theoretical possibility of exploitation,” Zoom says.

What the company did not say was how many vulnerability reports it received last year and how many of these led to the release of a patch. However, Zoom issued CVE identifiers for tens of critical- and high-severity flaws across its product portfolio.

Advertisement. Scroll to continue reading.

Earlier this year, Google said it paid out $12 million through its bug bounty programs in 2022. In comparison, Intel paid $935,000 in rewards last year, for a total of over $4.1 million since the beginning of its bug bounty program in 2017.

Related: QNAP Offering $20,000 Rewards via New Bug Bounty Program

Related: Hack the Pentagon 3.0 Bug Bounty Program to Focus on Facility Control Systems

Related: Apple Paid Out $20 Million via Bug Bounty Program

Related Content

Vulnerabilities

Successful exploitation of these flaws could lead to arbitrary code execution and information disclosure.

Vulnerabilities

Critical- and high-severity flaws could be exploited to execute arbitrary shell commands or elevate privileges.

Vulnerabilities

Fixes were rolled out for over two dozen vulnerabilities, including critical- and high-severity bugs.

Vulnerabilities

Ivanti and Zoom resolved security defects that could lead to arbitrary file writes, elevation of privilege, code execution, and information disclosure.

Cybercrime

North Korean hackers employ social engineering to trick Zoom Meeting participants into executing system-takeover commands.

Vulnerabilities

Juniper Networks, VMware, and Zoom have announced patches for dozens of vulnerabilities across their products.

Fraud & Identity Theft

North Korean cryptocurrency thieves abusing Zoom Remote collaboration feature to target cryptocurrency traders with malware.

Vulnerabilities

Ivanti, VMware, and Zoom released fixes for dozens of vulnerabilities in their products on April 2025 Patch Tuesday.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version