Google Paid Half of Its Vulnerability Rewards Towards Android, Chrome Bugs in 2018

Advertisement
By Jagmeet Singh | Updated: 9 February 2019 13:17 IST
Highlights
  • Google has paid out $15 million since the launch of its programme
  • In 2018, it rewarded $3.4 million to researchers
  • 1,319 individual rewards were distributed to 317 paid researchers

Google launched its Vulnerability Reward Programme back in November 2010

Google on Friday revealed that it has paid out as much as $15 million (roughly Rs. 106 crores) in rewards since the launch of its Vulnerability Reward Programme back in November 2010. In the last year alone, researchers were rewarded with a total amount of $3.4 million (roughly Rs. 24.19 crores) - of which, half of the amount was given towards reporting Android and Chrome vulnerabilities, the search giant revealed in a blog post. There were 1,319 individual rewards that were distributed to 317 paid researchers in 78 countries across the globe.

While elaborating the performance of its Vulnerability Reward Programme (VRP), Google in its blog post revealed that it rewarded $1.7 million (roughly Rs. 12 crores) for Android and Chrome vulnerabilities. This comes as half of the total $3.4 million worth of rewards the company gave in the year 2018.

"Back in 2010, we started the Vulnerability Reward Programme to get help from the security research community in identifying and reporting bugs in Google apps and software," Google's Program Manager of Security and Anti-abuse Research Oxana Comanescu and VRP Technical Lead Eduardo Vela Nava wrote in the joint blog post. "The goal of the programme is simple: encourage researchers to report issues so that we can fix them quickly and keep users' data secure. We also provide financial rewards for bug reporters, ranging from $100 to $200,000, based on the risk level of their discovery."

Advertisement

The biggest single reward that the Google Vulnerability Reward Programme distributed last year was $41,000 (roughly Rs. 29,17,000). The company also donated $181,000 (roughly Rs. 1.28 crores) to charity.

Advertisement

Amongst the most unique awardees of the initiative, the blog post has highlighted Uruguay's Ezequiel Pereira. The 19-year-old researcher had uncovered a Remote Code Execution "RCE" bug that allowed him to gain remote access to our Google Cloud Platform console. Similarly, Google has mentioned Tomasz Bojarski from Poland who had discovered a bug related to Cross-site scripting (XSS), a type of security bug that could allow an attacker to change the behaviour or appearance of a website, steal private data or perform actions on behalf of someone else. The Programme also saw the participation of Belarus from Minsk who works as a full-time bug hunter and is a part of VRP grants programme that offers financial support to "prolific bug-hunters" over time.

Last year, Google also brought Security and Privacy research awards that are aimed to "recognise academics who have made major contributions to the field" and are selected by a distinct committee of senior security and privacy researchers. Seven winners have emerged from the last year development for whom Google is donating more than $500,000 (roughly Rs. 3.5 crores) to their universities.

Advertisement

The list of academics receiving the Security and Privacy research awards include Alina Oprea of the Northeastern University for her contributions towards Cloud Security, Matthew Green of Johns Hopkins for the Cryptography field, Thorsten Holz of Ruhr-Universität for the area of Systems Security, Alastair Beresford of the Cambridge for the Usable security and privacy, mobile security field, Carmela Troncoso of École Polytechnique Usable de Lausanne for the Privacy / Security ML area, and Rick Wash of the Michigan State University for his contribution towards Usable Privacy and Security. There is also India-born Prateek Saxena of the National University of Singapore who contributed towards the field of ML/ Web security.

"Whether they're finding bugs today or making breakthroughs that will protect the Web years into the future, the security research community is making everyone's information safer online," Comanescu and Nava concluded.

Advertisement

Earlier this week, Google brought a new Chrome extension that suggests changing the password if any of your online account details are no longer safe due to a data breach. The company also recently created Adiantum, a special encryption method for entry-level Android smartphones.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. From iPhone 17 to New Apple Watch Models: What to Expect from Apple Event
  2. Amazon Great Indian Festival Sale: Deals on Smartphones, Laptops Teased
  3. Redmi 15 5G, Note 14 Pro Prices Dropped During Diwali With Xiaomi Sale
  4. Apple Rolls Out iOS 26 Beta 9 for iPhone Ahead of iPhone 17 Launch
  5. Realme Watch 5 Design, Key Features Leaked Ahead of Debut
  6. Realme 15T With 50-Megapixel Selfie Camera Debuts in India: See Price
  7. Apple Hebbal: First-Ever Apple Store in Bengaluru is Now Open
  8. Apple Marks iPhone 8 Plus as Vintage Alongside These MacBook Models
  9. Motorola Razr 60, Buds Loop With Swarovski Crystals Debut in India
  10. Vivo X300 Series to Use Samsung's New 200-Megapixel Sensor for Portraits
  1. Apple Rolls Out iOS 26 Beta 9 Update for iPhone With Bug Fixes Ahead of iPhone 17 Launch
  2. BCCI Says Crypto, Real Money Gaming Platforms Can’t Bid for Team India’s Title Sponsorship
  3. Scientists Discover Hidden Mantle Layer Beneath the Himalayas Challenging Century-Old Theory
  4. Astronomers Propose Rectangular Telescope to Hunt Earth-Like Planets
  5. Microsoft Testing Native Clipboard Sync Feature to Share Text Between Windows PCs, Android Devices
  6. Su From So OTT Release: When and Where to Watch This Kannada-Language Horror-Comedy Online
  7. Sennheiser Momentum 4 Wireless 80th Anniversary Edition Launched in India With Up to 60 Hour Battery Life
  8. Call of Duty Film Adaption Said to Be a 'Priority' at Paramount, Negotiations on to Acquire Rights
  9. Cannibal Solar Storm May Trigger Auroras as Powerful Geomagnetic Storm to Hit Earth Soon
  10. Apple's iPhone 8 Plus Listed as Vintage Product Ahead of iPhone 17 Launch, 11-Inch MacBook Air Now Obsolete
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.