Google bug bounty payments hit nearly $12 million in 2024

Application Security Testing Concept with Digital Magnifying Glass Scanning Applications to Detect Vulnerabilities - AST - Process of Making Apps Resistant to Security Threats - 3D Illustration
(Image credit: Shutterstock / ArtemisDiana)

  • Google bug bounties see 660 researchers get a share of $11.8 million in 2024
  • Chrome and Android VRPs were lucrative
  • Google’s VRP program turns 15 next year

Google has revealed it paid out $11.8 million in bug bounties in 2024, with payments going out to 660 security researchers, equating to a theoretical average of around $18,000 each.

Its highest payout in 2024 was $110,000, with its total payout to date now standing at $65 million since 2010.

Chrome researchers and those revealing vulnerabilities in Android and other Google Devices accounted for around half of 2024’s payouts, marking the company’s commitment to security within its most popular devices.

Google paid out $12 million in bug bounties last year

Some changes to the structures last year resulted in higher payout potentials, with the Google VRP now paying out up to $151,515, $300,000 for the Mobile VRP, $151,515 for the Cloud VRP and $250,000 for Chrome awards.

In a blog post, Google's Dirk Göhmann said researchers contributing to the Android and Google Devices Security Reward Program and the Google Mobile Vulnerability Reward Program got over $3.3 million in rewards in 2024, adding that 8% fewer reports were logged. However, the company did see a minor 2% increase in critical and high vulnerabilities.

A total of 337 unique reports were made to the Chrome VRP – 137 received rewards totalling an additional $3.4 million.

Google also celebrated the launch of a new category – 2024 was its first full year of AI bug bounties, but payouts remained relatively low, at $55,000.

Other successes include two bugSWAT events and four init.g workshops to support the next generation of security researchers.

Looking ahead, Göhmann noted the company will be celebrating 15 years of VRP in 2025 – it’s unclear whether any changes will be made to its VRPs to commemorate this milestone.

Göhmann added: “We want to send a huge thank you to our bug hunter community for helping us make Google products and platforms more safe and secure for our users around the world – and invite researchers not yet engaged with the Vulnerability Reward Program to join us in our mission to keep Google safe!”

You might also like

TOPICS
Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
A woman at a table using a Windows laptop, opposite sits a man, neither show their face
Microsoft will now pay you even more to find security bugs in Copilot
Facebook on laptop
Researcher nets major reward for finding Facebook bug able to unlock the gates to its internal systems
 In this photo illustration a Google Play logo seen displayed on a smartphone.
Over 2 million risky Android apps were blocked from the Play Store last year
the YouTube logo on a screen in front of other YouTube logos covering a black background
Worrying YouTube security flaw exposed billions of user emails
NordVPN
US hit with over 1.9 billion malware threats last year - here's how to stay safe
Chrome icon on Android
Google Chrome extensions hack may have started much earlier than expected
Latest in Security
person at a computer
Many workers are overconfident at spotting phishing attacks
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
Latest in News
European Union technical background
EU tech companies push for digital sovereignty, reducing reliance on US and others
Star Wars Knights of the Old Republic
Knights of the Old Republic remake developer Saber Interactive states all its projects are 'still in development'
google nest
Google is slowly phasing out its Assistant helper to make room for Gemini's reign in smartphones - here’s how it’s doing the same for smart home devices
Renault 5 Turbo 3E
Renault unveils its wildest EV to date and it comes with in-wheel motors and a rally-style vertical handbrake for drifting
Circular smart ring
Circular's new smart ring is getting blood pressure and blood glucose monitoring before the Apple Watch
Gemini on a mobile phone.
Worryingly, Google Gemini’s new AI image generation features can be used to remove watermarks from images and I'm concerned