Cyber Security News

Google’s Bug Bounty Program Hits Record $17 Million in 2025 Payouts

Google has announced a record-breaking year for its Vulnerability Reward Program (VRP). In 2025, the tech giant paid out more than $17 million to ethical hackers worldwide to help secure its platforms.

This major milestone marks a massive 40% increase compared to 2024 and perfectly aligns with the program’s 15th anniversary.

Vulnerability Reward Program 2025 in Numbers (Source: Google )

Over 700 security researchers across the globe received financial rewards for discovering and reporting critical vulnerabilities before malicious actors could exploit them.

One of the most significant changes in 2025 was Google’s heightened focus on artificial intelligence security.

Google launched a dedicated AI Vulnerability Reward Program to offer researchers clearer testing scopes and better reward guidelines.

Previously, AI vulnerabilities fell under the general Abuse VRP, but the technology’s rapid growth required a specialized approach.

Additionally, the Chrome browser VRP expanded its rules to include specific reward categories for security flaws discovered in AI features, such as Gemini integrations.

Live Hacking and Open Source Security

Google also invested heavily in live hacking events and open-source security tools throughout the year.

The company introduced a new patch reward program for OSV-SCALIBR, an open-source tool designed to find vulnerabilities in software dependencies.

Contributors who provided novel scanning plugins were rewarded, and these external submissions have already helped Google uncover and remediate leaked secrets internally.

On the community front, Google hosted multiple invite-only bugSWAT live hacking events globally, bringing top researchers together to hunt for high-impact bugs. Key event highlights included:

  • Tokyo AI bugSWAT in April generated over 70 reports, resulting in more than $400,000 in rewards.
  • Sunnyvale Cloud bugSWAT in June led to 130 reports, paying out an impressive $1.6 million to participants.
  • Las Vegas bugSWAT in August secured 77 reports, issuing $380,000 to security researchers.
  • Mexico City bugSWAT focused on AI, Android, and Cloud targets, generating 107 reports and $566,000 in payouts.

As cyber threats continue to evolve, Google remains committed to collaborating with the external security community.

In 2026, the company plans to host several more bugSWAT events and the next edition of its ESCAL8 cybersecurity conference.

By working closely with independent researchers and rewarding their efforts, Google aims to stay ahead of emerging threats and continuously strengthen the security of its global products and services.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Google Search Makes It Harder to See Where a Link Really Goes Before You Click

Google has begun routing some organic Search result links through opaque google.com/goto?url=... redirects, reducing users’…

12 hours ago

Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters

Phishing operators are increasingly shifting away from malware-laden attachments and toward trusted delivery services, authenticated…

13 hours ago

Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors

Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin…

14 hours ago

Weekly Cybersecurity Newsletter – Top 50 Biggest Cybersecurity Stories of the Week

Microsoft Patches 973 CVEs, Claude Agents Automate Attacks, China Chains Chrome Zero-Day, Cisco FMC Exploited…

14 hours ago

WordPress Events Calendar Vulnerabilities Let Hackers Take Over 600,000 Websites

Two critical unauthenticated vulnerability chains in the widely used The Events Calendar WordPress plugin could…

14 hours ago

Red Heron Hackers Exploit Critical Gitea RCE to Steal Source Code and Deploy Linux Rootkit

A Chinese-speaking threat actor known as Red Heron has exploited a critical remote code execution…

14 hours ago