Google's $17.1 Million Bug Bounty in 2025 Highlights Security Research Value

Google's $17.1 Million Bug Bounty in 2025 Highlights Security Research Value

First seen 13 Mar 2026, 11:29 UTC BleepingcomputerFeeds.FeedburnerTechradarScworldEscudodigital 83% similarity 21.9

Article Content

Browse articles
ThreatCluster

In 2025, Google awarded over $17 million to 747 security researchers through its Vulnerability Reward Program (VRP), marking a 40% increase from the previous year. The program has paid out over $81.6 million since its inception in 2010. Notable payouts included over $3.7 million for Chrome vulnerabilities and more than $3.5 million for cloud security defects. The highest individual reward in 2025 was $250,000. Google emphasized the importance of collaboration with the external security research community to enhance the safety of its products. The VRP also introduced new categories targeting AI vulnerabilities and launched a rewards program for its open-source tool OSV-SCALIBR. The Android and Google Devices Security Reward Program contributed over $2.9 million to the total. The initiative reflects Google's commitment to staying ahead of emerging threats and adapting to evolving technologies.

Key Points: • Google paid $17.1 million to 747 researchers in 2025, a 40% increase from 2024. • The highest individual reward was $250,000 for a reported vulnerability. • New programs were launched for AI vulnerabilities and open-source security flaws.

ThreatCluster AI

Timeline

2025-01-01
2025 VRP payouts began
2025-12-31
2025 VRP payouts totaled over $17 million
2026-03-12
Article published detailing 2025 VRP payouts

Community

Browse all →