Google paid its highest-ever bug bounty last year

dollar
Image Credit: Akspic (Image credit: Future)

Someone made a lot of money discovering vulnerabilities in Google products in 2022, the company has revealed.

The search engine giant recently disclosed the results of its Vulnerability Reward Program, a bug bounty campaign that rewards ethical hackers who discover major flaws in its products and disclose them responsibly instead of giving hackers an opportunity to abuse them with malware

In total, the company paid out more than $12 million for roughly 2,900 vulnerabilities over the course of 2022.

Flaws in Android, Chrome, and ChromeOS

One unique report stands out in Google's report - a hacker discovered an exploit chain, involving five separate vulnerabilities in Android - CVE-2022-20427, CVE-2022-20428, CVE-2022-20454, CVE-2022-20459, CVE-2022-20460. Google decided the exploit chain warranted a $605,000 reward. 

The person who discovered the exploit chain goes by the alias gzobqq, BleepingComputer reported, adding that the same person earned $157,000 in 2021, as well, for a critical exploit chain in Android. Both these exploit chains were the highest bug bounty in Android at their respective times. 

Looking at Android specifically, last year Google paid out $4.8 million in rewards. The three most active hackers reported 200, 150, and 100 bugs, respectively.

Furthermore, the company paid out almost $500,000 for 700 reports done through the Android Chipset Security Reward Program. ACSRP is a private bug bounty program reserved only for Android chipset manufacturers. 

For 363 flaws discovered in Chrome, and 110 in ChromeOS, Google paid out $4 million.

Most major tech companies operate bug bounty programs, as they are a great way to incentivize the wider cybersecurity community to participate in the strengthening of the world’s most popular software. 

In August 2022, Microsoft reported paying out $13.7 million in rewards, to 330 security researchers across 46 countries. The largest award, under the Hyper-V Bounty Program, was $200,000, the company added, while the average award was approximately $12,000.

Apple, on the other hand, said it paid out $20 million via its bug bounty program in 2022, with the average reward in the product category being $40,000.

Via: BleepingComputer

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Application Security Testing Concept with Digital Magnifying Glass Scanning Applications to Detect Vulnerabilities - AST - Process of Making Apps Resistant to Security Threats - 3D Illustration
Google bug bounty payments hit nearly $12 million in 2024
A woman at a table using a Windows laptop, opposite sits a man, neither show their face
Microsoft will now pay you even more to find security bugs in Copilot
Facebook on laptop
Researcher nets major reward for finding Facebook bug able to unlock the gates to its internal systems
the YouTube logo on a screen in front of other YouTube logos covering a black background
Worrying YouTube security flaw exposed billions of user emails
 In this photo illustration a Google Play logo seen displayed on a smartphone.
Over 2 million risky Android apps were blocked from the Play Store last year
chrome firefox extensions
Google Chrome extensions hit in major attack - dozens of developers affected, so be on your guard
Latest in Software & Services
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
Autonomous finance
Quickbooks vs Quicken: what are the main strengths and weaknesses for your business
finance
Quickbooks vs Xero: which is the best for your business?
Group of people meeting
Zoom vs Google Meet: which is the best video conferencing tool for your business?
Fingers typing on a computer keyboard.
Microsoft 365 Personal vs Microsoft 365 Family: are there any real differences?
Person at laptop
Windows 11 vs Windows 365: which is the best choice for businesses?
Latest in News
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 16 (game #1147)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 16 (game #378)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 16 (game #644)
Three iPhone 16 handsets on show
Apple could launch an iPhone 17 Ultra this year – but we've heard these rumors before
Super Mario Odyssey
ChatGPT is the ultimate gaming tool - here's 4 ways you can use AI to help with your next playthrough