Vulnerability Reward Program: ... Note

Vulnerability Reward Program: 2024 in Review

In 2024, Google's Vulnerability Reward Program awarded nearly $12 million to over 600 security researchers worldwide. The program made several changes, including revamping its reward structure, introducing a new payment option, and hosting bug-hunting events. The Mobile VRP now offers up to $300,000 for critical vulnerabilities in top-tier apps, while the Cloud VRP has a top-tier award of up to $151,515. The Abuse VRP saw a 40% year-over-year increase in payouts, with over 250 valid bugs reported. Google also hosted two editions of bugSWAT, a training and hacking event, and four init.g workshops to support the next generation of security engineers. The Android and Google Devices Security Reward Program awarded over $3.3 million in rewards to researchers who uncovered critical vulnerabilities. The Chrome VRP updated its reward amounts and structure, and received 337 reports of unique, valid security bugs in 2024. The Cloud VRP launched in October and has triaged over 400 reports, filing over 200 unique security vulnerabilities for Google Cloud products and services. Google's Generative AI bug bounty program received over 150 bug reports, leading to key improvements and over $55,000 in rewards. In 2025, Google will celebrate 15 years of its Vulnerability Reward Program, focusing on expanding scope and continuing to strengthen the security posture of its products and services.