Wednesday, September 16, 2026

Google’s Bug Bounty Program Hits Record $17 Million in 2025 Payouts

Google has announced a record-breaking year for its Vulnerability Reward Program (VRP). In 2025, the tech giant paid out more than $17 million to ethical hackers worldwide to help secure its platforms.

This major milestone marks a massive 40% increase compared to 2024 and perfectly aligns with the program’s 15th anniversary.

Vulnerability Reward Program 2025 in Numbers (Source: Google )
Vulnerability Reward Program 2025 in Numbers (Source: Google )

Over 700 security researchers across the globe received financial rewards for discovering and reporting critical vulnerabilities before malicious actors could exploit them.

One of the most significant changes in 2025 was Google’s heightened focus on artificial intelligence security.

Google launched a dedicated AI Vulnerability Reward Program to offer researchers clearer testing scopes and better reward guidelines.

Previously, AI vulnerabilities fell under the general Abuse VRP, but the technology’s rapid growth required a specialized approach.

Additionally, the Chrome browser VRP expanded its rules to include specific reward categories for security flaws discovered in AI features, such as Gemini integrations.

Live Hacking and Open Source Security

Google also invested heavily in live hacking events and open-source security tools throughout the year.

The company introduced a new patch reward program for OSV-SCALIBR, an open-source tool designed to find vulnerabilities in software dependencies.

Contributors who provided novel scanning plugins were rewarded, and these external submissions have already helped Google uncover and remediate leaked secrets internally.

On the community front, Google hosted multiple invite-only bugSWAT live hacking events globally, bringing top researchers together to hunt for high-impact bugs. Key event highlights included:

  • Tokyo AI bugSWAT in April generated over 70 reports, resulting in more than $400,000 in rewards.
  • Sunnyvale Cloud bugSWAT in June led to 130 reports, paying out an impressive $1.6 million to participants.
  • Las Vegas bugSWAT in August secured 77 reports, issuing $380,000 to security researchers.
  • Mexico City bugSWAT focused on AI, Android, and Cloud targets, generating 107 reports and $566,000 in payouts.

As cyber threats continue to evolve, Google remains committed to collaborating with the external security community.

In 2026, the company plans to host several more bugSWAT events and the next edition of its ESCAL8 cybersecurity conference.

By working closely with independent researchers and rewarding their efforts, Google aims to stay ahead of emerging threats and continuously strengthen the security of its global products and services.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Google Search Makes It Harder to See Where a Link Really Goes Before You Click

Google has begun routing some organic Search result links...

Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters

Phishing operators are increasingly shifting away from malware-laden attachments...

Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors

Threat actors are actively exploiting a critical vulnerability in...

Weekly Cybersecurity Newsletter – Top 50 Biggest Cybersecurity Stories of the Week

Microsoft Patches 973 CVEs, Claude Agents Automate Attacks, China...

WordPress Events Calendar Vulnerabilities Let Hackers Take Over 600,000 Websites

Two critical unauthenticated vulnerability chains in the widely used...

Telegram Desktop XSS Vulnerability Lets Attackers Steal Entire Chat Histories

A stored cross-site scripting (XSS) vulnerability in Telegram Desktop...

Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds

A threat actor exploited a critical pre-authentication remote code...

Related Articles

Recent News