Google Surpasses $15 Million in Bug Bounty Payouts to Security Researchers

Google pays out $3.4 million to 317 researchers in 2018, bringing its total bug bounty spending to over $15 million since 2010. The program rewards hackers for finding and responsibly disclosing vulnerabilities rather than exploiting them.

Google announces it pays out over $15 million to security researchers since launching its bug bounty program in 2010. The company distributes $3.4 million to 317 different researchers in 2018 alone, which is an increase from the $2.9 million given to 274 researchers the previous year. Half of last year's total rewards, amounting to $1.7 million, goes to individuals who find and report vulnerabilities in Android and Chrome.

Bug bounty programs serve as a valuable complement to internal security efforts by incentivizing hackers to disclose flaws properly instead of selling or exploiting them maliciously. Google's financial rewards for security bugs range from $100 to $200,000 depending on the risk level, with the largest single payout in 2018 reaching $41,000. The company also supports prolific bug hunters through its VRP grants program, providing financial assistance even when they do not find an active bug.

Notable 2018 discoveries include a Remote Code Execution bug found by a 19-year-old researcher that grants remote access to the Google Cloud Platform console. The year's top bug hunter uses his reward money to open a lodge and restaurant in Poland after discovering a critical cross-site scripting flaw. Google continues to expand the program to cover more products and offers highly lucrative rewards such as up to $100,000 for hacking a Chromebook and up to $200,000 for compromising Android.

Read More at the original source →