Last year, Google offered the largest reward for finding and reporting a critical exploit chain through its bug bounty program (about $605,000). In total, Google has given out over $12 million for finding and reporting 2,900 vulnerabilities in its products.

Android bug bounties
Google has released data for its 2022 Vulnerability Reward Programs (VRPs), showing how security researchers participating in the bug bounty helped improve the level of security across the company's products .
As we mentioned above, the company gave the largest payout for a report of an exploit chain of five bugs (CVE-2022-20427, CVE-2022-20428, CVE-2022-20454, CVE-2022-20459, CVE-2022-20460) in Android. It was reported by gzobqq and the reward reached $605,000.
See also: Google: Investigating Gmail IMAP sync issues affecting Outlook
In 2021, the same researcher discovered another exploit chain on Android and received $157,000.
Typically, the reward for Android vulnerabilities submitted through Google VRP is up to $10,000, but for exploit chains, the company pays up to $1 million.
In 2022, Google paid $4.8 million in bug bounties for hundreds of Android bugs.
The researchers who had found and reported the most errors were:
- Aman Pandey (more than 200 errors)
- Zinuo Han (150 errors)
- Yu-Cheng Lin (almost 100 errors)
Additionally, Google gave out $486,000 last year for 700 reports through the Android Chipset Security Reward Program (ACSRP).
Chrome and OSS fees
In 2022, the company also awarded over $4 million for 363 vulnerabilities discovered in the Chrome Browser and 110 security issues in ChromeOS.

As for the open-source bounty program that launched in August 2022, it awarded more than 100 bug hunters with over $110,000.
See also: Florida: Asks Google and Apple to flag "foreign" apps
In addition to the rewards provided to security researchers through the bug bounty program, Google has also awarded more than $250,000 in grants to more than 170 researchers. These funds are available for people who monitor Google products and services, even if they don't discover any vulnerabilities.
In 2022, Google paid 703 researchers from 68 countries for reports submitted through its Vulnerability Rewards Programs and was a sponsor for the security-related conferences NahamCon and BountyCon.
Google said of the researchers and their work: “Without our incredible security researchers we wouldn’t be here to share this amazing news today. Thank you again for your continued hard work… Thank you for helping make Google, the Internet, and our users safer!”
See also: Google Pixel 7: Doesn't support the newest 5G standard
Bug bounty programs offer numerous benefits to organizations (like Google) looking to improve their cybersecurity posture, while also saving time and money. By encouraging external researchers to test systems for vulnerabilities, businesses can quickly identify potential issues, while also benefiting from increased awareness of security issues in the broader community. Additionally, offering rewards for successful submissions can incentivize researchers to continue participating in these programs, ultimately making everyone safer online!
Source: www.bleepingcomputer.com
