Site navigation

How Much Did Google Pay in Bug Bounties Last Year?

Michael Edgar

,

Alleged Leaked Doc Suggests Google Falling Behind in AI Race Google bug bounty
Google dishes out hefty sums for bug bounties as researchers uncover thousands of vulnerabilities.

In an ongoing effort to fortify the security of its products and services, Google announced in its ‘year in review’ security blog that it paid out a staggering $10 million (£7.8m) in bug bounties in 2023. 

The sum was distributed among over 600 white hackers from 68 different countries. The bug bounty programme is a cornerstone of Google’s cybersecurity strategy, and encourages ethical hackers to identify and report vulnerabilities before they can be exploited by malicious actors. 

As cybersecurity remains a paramount concern in today’s digital landscape, the contributions of ethical hackers play a pivotal role in safeguarding user data and maintaining trust in online platforms.

Notably, the highest single payment reached an impressive $113,337. While this year’s payout was a slight reduction from the $12m (£9.3m) dispersed in 2022, the amount given still underscores the critical role played by these researchers in bolstering the defences. 

Since the inception of its bug bounty program in 2010, Google has allocated a total of $59m ($46.2m) in rewards to researchers. Particular attention is paid to securing the android ecosystem, and in the most recent report, about a third (£2.6m) of rewards were distributed to researchers who unearthed vulnerabilities within Android. 

Furthermore, Google expanded its bug bounty program to encompass Wear OS, the operating system designed for smartwatches and wearables. 

The tech giant also implemented various enhancements to its Chrome Vulnerability Rewards Program (VRP) in 2023, paying out £1.6m for 359 unique reports of Chrome Browser security bugs. 


Recommended reading


Additionally, Google intensified its focus on securing AI systems, organising the bugSWAT live-hacking event to uncover vulnerabilities in its large language model (LLM) products. This initiative resulted in payments exceeding £68k from 35 reports, highlighting the efficacy of collaborative efforts in enhancing the safety of AI systems.

“We remain committed to fostering collaboration, innovation, and transparency with the security community. Our ongoing mission is to stay ahead of emerging threats, adapt to evolving technologies, and continue to strengthen the security posture of Google’s products and services. We look forward to continuing to drive greater advancements in the world of cybersecurity,” concluded Google in its blog post. 

“A huge thank you to our bug hunter community for helping to make Google products and platforms more safe and secure for our users around the world!”

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data