Monday, September 28, 2026
HomeCyber SecurityGoogle On-line Safety Weblog: Vulnerability Reward Program: 2021 Yr in Overview

Google On-line Safety Weblog: Vulnerability Reward Program: 2021 Yr in Overview

[ad_1]

Final yr was one other document setter for our Vulnerability Reward Packages (VRPs). All through 2021, we partnered with the safety researcher neighborhood to establish and repair 1000’s of  vulnerabilities – serving to hold our customers and the web secure. 

Thanks to those unimaginable researchers, Vulnerability Reward Packages throughout Google continued to develop, and we’re excited to report that in 2021 we awarded a document breaking $8,700,000 in vulnerability rewards – with researchers donating over $300,000 of their rewards to a charity of their alternative. 

We additionally launched bughunters.google.com in 2021, a public researcher portal devoted to preserving Google merchandise and the web secure and safe. This new platform brings all of our VRPs (Google, Android, Abuse, Chrome, and Google Play) nearer collectively and offers a single consumption type, making safety bug submission simpler than ever. We’re enthusiastic about every part the brand new Bug Hunters portal has to supply, together with:

  • Extra alternatives for interplay and a little bit of wholesome competitors by way of gamification, per-country leaderboards, awards/badges for sure bugs, and extra!

  • A extra practical and aesthetically pleasing leaderboard. We all know a variety of you might be utilizing your achievements in our VRPs to search out jobs (we’re hiring!) and we hope this acts as a helpful useful resource.

  • A stronger emphasis on studying: bug hunters can enhance their expertise by way of the content material accessible in our new Bug Hunter College

  • Streamlined publication course of: we all know the worth that information sharing brings to our neighborhood. That’s why we need to make it simpler so that you can publish your bug studies.

  • We now provide swag! The primary 20 people who share this weblog submit on Twitter and tag @GoogleVRP will obtain a present voucher for swag of their DMs.  

As in previous years, we’re sharing our 2021 Yr in Overview statistics throughout all of our applications. We want to give a particular thanks to all of our devoted researchers – we look ahead to extra collaboration sooner or later!

Android

The Android VRP doubled its 2020 whole payouts in 2021 with almost $3 million {dollars} in rewards, and awarded the very best payout in Android VRP historical past: an exploit chain found in Android receiving a reward of $157,000!

Our business main prize of $1,500,000 for a compromise of our Titan-M Safety chip utilized in our Pixel machine stays unclaimed – for extra info on this reward and Android exploit chain rewards, please go to our public guidelines web page. 

This system additionally launched the Android Chipset Safety Reward Program (ACSRP), a vulnerability reward program provided by Google in collaboration with producers of sure in style Android chipsets. This non-public, invite-only program, offers reward and recognition for contributions of safety researchers who make investments their effort and time into serving to make Android gadgets safer. In 2021 the ACSRP paid out $296,000 for over 220 legitimate and distinctive safety studies.  

We want to give a particular shoutout to a few of our high researchers whose continued arduous work retains Android secure and safe:

  • Aman Pandey of Bugsmirror Workforce has skyrocketed to our high researcher final yr, submitting 232 vulnerabilities in 2021! Since submitting their first report in 2019, Aman has reported over 280 legitimate vulnerabilities to the Android VRP and has been a vital a part of making our program so profitable.

  • Yu-Cheng Lin (林禹成) (@AndroBugs) has been one other phenomenal researcher for the Android VRP, submitting a whopping 128 legitimate studies to this system in 2021. 

  • Researcher gzobqq@gmail.com found a crucial exploit chain in Android (CVE-2021-39698) , receiving the very best payout in Android VRP historical past of $157,000. 

Chrome

This yr the Chrome VRP additionally set some new data – 115 Chrome VRP researchers have been rewarded for 333 distinctive Chrome safety bug studies submitted in 2021, totaling $3.3 million in VRP rewards. The contributions not solely assist us to enhance Chrome, but additionally the online at massive by bolstering the safety of all browsers based mostly on Chromium.

Of the $3.3 million, $3.1 million was awarded for Chrome Browser safety bugs and $250,500 for Chrome OS bugs, together with a $45,000 high reward quantity for an particular person Chrome OS safety bug report and $27,000 for an particular person Chrome Browser safety bug report.

Of those totals, $58,000 was awarded for safety points found by fuzzers contributed by VRP researchers to the Chrome Fuzzing program. Every legitimate report from an externally supplied fuzzer acquired a $1,000 patch bonus, with one fuzzer report receiving a $16,000 reward.

The Chrome VRP wouldn’t be capable to smash these data during the last yr with out the efforts of so many distinctive VRP researchers. We’d like to spotlight a couple of researcher achievements made in 2021:

  • Rory McNamara, a Chrome OS VRP researcher who has been collaborating within the Chrome VRP for 5 years, turned the very best awarded Chrome VRP researcher of all time. This yr he was rewarded for six studies attaining root privilege escalation in Chrome OS, considered one of which acquired the very best reward quantity achieved for a single Chrome bug report in 2021 at $45,000. 

  • Chrome Browser VRP researcher Leecraso (@leecraso) of 360 Vulnerability Analysis Institute was essentially the most awarded researcher of 2021, with 18 legitimate bug studies; a majority of which have been for reminiscence corruption vulnerabilities affecting the browser course of.

 

  • We love when researchers write about their findings (solely after we now have publicly disclosed the bug, in fact)! Chrome Browser VRP researcher Brendon Tiszka wrote a superb two-part weblog collection on his discovery and exploitation of a V8 vulnerability, CVE-2021-21225, the evaluation and reporting of which earned him a $22,000 VRP reward.

Large thanks and congratulations to all Chrome VRP researchers that helped us make Chrome and Chrome OS extra secure for all customers in 2021!.

Google Play

Google Play paid out $550,000 in rewards to over 60 distinctive safety researchers.

The Google Play Safety Reward Program additionally launched their Android App Hacking Workshop content material and revealed a weblog on their work to empower the following era of Android Utility Safety Researchers. 

kCTF VRP

In November we expanded our reward quantities for exploits towards our kCTF cluster from 5,000-10,000 as much as 31,337-50,337 USD. Within the final 3 months we have been completely satisfied to have a number of members obtain $175,685 USD in rewards. We additionally prolonged the timeline of the elevated rewards till February 14 (from January 31) which ought to give everybody a pair extra weeks to finalize any almost-working exploits.

GCP VRP Prize

To encourage safety researchers to give attention to Google Cloud Platform, we initiated the annual GCP VRP Prize in 2019. In March this yr, we introduced the winners of the 2020 version of the prize and paid out $313,337 in prizes. Ezequiel Pereira received the highest prize of $133,337 for locating an RCE in Google Cloud Deployment Supervisor. We noticed some superb analysis on Google Cloud Platform this yr too. Keep tuned for the 2021 winners!

Analysis Grants

Six years in the past, the Google VRP launched an experimental Vulnerability Analysis Grant program to encourage seasoned safety researchers to take an in depth and intensive look into the safety of Google services and products. And reward them even when there are not any vulnerabilities discovered. Six years later, we’re completely satisfied to announce that in 2021 we awarded over $200,000 in grants to greater than 120 safety researchers around the globe. 

If you’re a Google VRP researcher and need to be thought-about for a Vulnerability Analysis Grant be sure to opted in in your bughunters profile.

Trying ahead

With the launch of the brand new Bug Hunters portal, we plan to proceed bettering our platform and listening to you – our researchers – on methods we are able to enhance our platform and Bug Hunter College. 

Thanks once more for making Google, the Web, and our customers secure and safe! Comply with us on @GoogleVRP

Thanks to Adam Bacchus, Dirk Göhmann, Sarah Jacobus, Amy Ressler, Martin Straka, Jan Keller, Jon Bottarini



[ad_2]

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular

Recent Comments