HomeSecurityGoogle Vulnerability Reward Program: Rewards of $17 million in 2025

Google Vulnerability Reward Program: $17 million in rewards in 2025

In 2025, Google’s Vulnerability Reward Program (VRP) celebrated its 15th anniversary, setting a new record for security researcher payouts . The company awarded a total of $17 million to ethical hackers , a 40% increase over 2024 and reaffirming the importance of collective efforts to protect digital infrastructure. More than 700 external researchers responsibly identified and reported critical vulnerabilities, highlighting the continued need for community-based security research.

Google Vulnerability Reward Program

Vulnerability Reward Program: Focus on artificial intelligence and new threats

Artificial intelligence became the focus of Google’s security strategy in 2025. In response to the growing threats associated with machine learning models, Google launched the dedicated AI Vulnerability Reward Program, providing clear boundaries and reward categories for AI-related exploits. This autonomous category expands the traditional VRP for abuse and adapts rules and practices to the new security needs imposed by intelligent models.

See also: CISA: TrueConf vulnerability in KEV Directory

Chrome bug bounty: AI and Gemini in the spotlight

Chrome’s VRP now has dedicated categories for flaws related to built-in AI capabilities and the Gemini framework. Active community participation contributed significantly to the impressive results in 2025, with a high number of reports and significant payouts. Google also hosted multiple bugSWAT, a series of invite-only live hacking events focused on high-priority attack surfaces.

Notable incidents included: Sunnyvale Cloud bugSWAT, with 130 reports and $1.6 million in rewards, Tokyo AI bugSWAT, with 70 reports and $400,000, Mexico City bugSWAT, with 107 reports and $566,000, and Las Vegas bugSWAT, with 77 verified reports and $380,000 in payouts.

OSV-SCALIBR and open source security

Google isn’t just limited to products and apps. In 2025, it launched a unique bounty program for OSV-SCALIBR, an open-source tool that finds vulnerabilities in software dependencies. Researchers who create add-ons for the tool earn rewards for improving the detection of repositories or secrets, strengthening security in internal and external systems.

See also: Critical vulnerabilities in TP-Link Tapo C520WS cameras

Google Vulnerability Reward Program: $17 million in rewards in 2025

ESCAL8: The global dimension of security

Google strengthened its global presence with ESCAL8, a security conference in Mexico City that included technical leadership seminars, student workshops, and the final Capture the Flag HACKCELER8. The event enhanced community education and engagement, while demonstrating the importance of international collaborations for software security.

Strategy for 2026: Crowdsourcing and bug bounty

Now, Google is planning new global bugSWAT events and the next edition of ESCAL8, maintaining the momentum built in 2025. The continuous evolution of threat actors makes crowdsourcing security research one of the most effective defense tools against complex and emerging cyberthreats .

See also: Critical vulnerability in Claude Code comes after code leak

Google Vulnerability Reward Program: $17 million in rewards in 2025

The focus on artificial intelligence, open source support, and global collaboration demonstrate a long-term strategy for protecting critical infrastructure. As technology platforms become increasingly complex, the collective participation of the research community remains critical to preventing and addressing vulnerabilities. Google is demonstrating that continued investment in bug bounties is not just a cost, but a strategic advantage for the security of the digital ecosystem.

VRP continues to set the bar for global software security, combining technology, community, and strategic foresight to address the threats of the future. The record-breaking 2025 payouts are just the beginning of an ongoing effort for a safer internet and more reliable AI tools.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS