Security News > 2021 > July > Google Paid Over $29 Million in Bug Bounty Rewards in 10 Years

Google Paid Over $29 Million in Bug Bounty Rewards in 10 Years
2021-07-27 16:06

Google says it has paid more than $29 million in rewards for pre-patch vulnerability data over the past 10 years.

Since the launch of Google Vulnerability Rewards Program 10 years ago, the company said it paid bounties on 11,055 vulnerabilities that were reported by 2,022 researchers from 84 countries.

With the new website, Google wants to make it easier for researchers to submit security flaw discoveries, while also offering a series of additional improvements, such as more interaction opportunities, a redesigned leaderboard, the opportunity for researchers to improve their skills at a Bug Hunter University, a streamlined process for publishing bug reports, and more.

Google said researchers may receive rewards for patches submitted to open-source software, as well as for research papers on the security of open source.

What's more, subsidies may be offered to open-source software, the company says.

"Since its inception, the VRP program has not only grown significantly in terms of report volume, but the team of security engineers behind it has also expanded - including almost 20 bug hunters who reported vulnerabilities to us and ended up joining the Google VRP team," Google said.


News URL

http://feedproxy.google.com/~r/securityweek/~3/fhQa0c_gzuQ/google-paid-over-29-million-bug-bounty-rewards-10-years

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Google 102 253 4216 4506 727 9702