Google is launching kvmCTF , a new vulnerability reward program (VRP), first announced in October 2023, aimed at strengthening the security of its Kernel-based Virtual Machine (KVM) hypervisor . The company said that under this VRP program, it will award up to $250,000 to researchers who discover and report complete VM escape exploits.

KVM (open-source hypervisor) is a critical component in consumer and enterprise settings, powering the Android and Google Cloud.
As an active and key contributor to KVM, Google developed kvmCTF to help identify and fix vulnerabilities, strengthening its security.
See also: Cisco fixes zero-day vulnerability in NX-OS
Like Google's kernelCTF bounty program, which targets security , kvmCTF focuses on flaws in the Kernel-based Virtual Machine (KVM) hypervisor, which are accessible from VMs.
The goal is to perform successful guest-to-host attacks. QEMU or host-to-KVM vulnerabilities will not receive rewards.
Security researchers participating in Google's kvmCTF program will have a controlled lab environment where they can use their exploits to identify vulnerabilities. However, unlike other similar programs, kvmCTF focuses on zero-day vulnerabilities rather than known bugs.
Zero-day vulnerabilities are security holes that have not been discovered or patched by software vendors. The term 'zero-day' refers to the fact that developers have zero days to fix the problem before it is exploited by malicious users.
See also: Hackers exploit vulnerability in D-Link DIR-859 routers
Zero-day vulnerabilities are particularly dangerousbecause there are no updates or patches available to address them. This means that users and organizations are vulnerable to attacks until the vulnerability.
The importance of zero-day vulnerabilities lies in the fact that they can be used to perform malicious actions such as stealing data, installing malware, or gaining unauthorized access to systems. These attacks can have serious consequences for the security and privacy of users.
Detecting and addressing zero-day vulnerabilities is critical to system security. That's why technology like Google invest significant amounts of money in discovering and fixing these vulnerabilities, offering rewards to security researchers who find them.
Google kvmCTF: The reward levels are:
- Full VM escape: $250,000
- Arbitrary memory write: $100,000
- Arbitrary memory read: $50,000
- Relative memory write-down: $50,000
- Denial of service: $20,000
- Relative memory read: $10,000

The kvmCTF infrastructure is hosted in Google's Bare Metal Solution (BMS) environment
Security researchers will gain access to the Guest VM and attempt to perform a guest-to-host attack. The goal of the attack is to exploit a zero-day vulnerability in the KVM subsystem of the host kernel.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Juniper Networks patches serious “auth bypass” vulnerability
“If the attack is successful, the attacker will receive a flag proving their achievement in exploiting the vulnerability. The severity of the attack will determine the amount of the reward, which will be based on the reward tier system explained above. All reports will be thoroughly evaluated on a case-by-case basis,” said software engineer Marios Pomonis.
Participants should review the kvmCTF rules before launching their attacks.
Source: www.bleepingcomputer.com
