Poking holes in Google tech bagged bug hunters $10M
(2024/03/13)
- Reference: 1710352814
- News link: https://www.theregister.co.uk/2024/03/13/google_2023_bug_bounties/
- Source link:
Google awarded $10 million to 632 bug hunters last year through its vulnerability reward programs.
The web goliath's 2023 total represents a slight dip compared to the [1]$12 million in bounties it paid the previous year. Hopefully this means more-secure products — not more researchers [2]turning to the dark side and making money selling exploits instead of disclosing them to vendors.
For comparison, consider that Microsoft paid out $13.8 million to 345 researchers between July 1, 2022, and June 30, 2023, according to Redmond's most recent rewards totals.
[3]
Google's 2023 highlights include newer reward categories, including finding flaws in its AI products and Android phone apps, plus a brand-new [4]Bonus Awards program that periodically pays out time-limited, extra rewards for specific vulnerability targets.
[5]
[6]
The single biggest reward last year hit $113,337, although the [7]year-in-review post doesn't say which program paid that amount and to whom.
Some of 2023's high-paying categories included Android VRP, which awarded more than $3.4 million to researchers who spotted Android device vulnerabilities. Google also last year [8]increased the max-reward amount to $15,000 for critical Android bugs, and launched a new [9]Mobile VRP that focuses on first-party Android apps.
[10]
Google also added Wear OS to the bounty program to encourage bug hunters to poke around in its smartwatches and other wearable tech. And in a live hack-a-thon for Wear OS and Android Automotive OS, bug bounty recipients received $70,000 for finding more than 20 critical vulnerabilities.
Google has also encouraged ethical hackers to [11]test for five categories of attacks in its AI products.
Last year, the Android juggernaut ran a bugSWAT live-hacking event targeting LLM products that produced 35 reports, totaling more than $87,000 rewards. These included [12]Hacking Google Bard - From Prompt Injection to Data Exfiltration and [13]We Hacked Google A.I. for $50,000 .
Chrome rewards
Jacobus describes 2023 as "a year of changes and experimentation" for Google's [14]Chrome VRP , which awarded $2.1 million to bug hunters who spotted 359 unique Chrome vulnerabilities in 2023.
Chrome calls its major new versions "milestones," and with milestone 116 passed in August, Google added [15]MiraclePtr — this is technology to prevent exploitation of use-after-free bugs — across all Chrome platforms.
[16]
This resulted in fewer vulnerability reports and lower rewards. However, the Chrome VRP has also added the [17]MiraclePtr Bypass Reward , which pays up to $100,115, to encourage researchers to try to find ways to bypass this security feature.
It also launched the [18]Full Chain Exploit Bonus , which pays triple the usual reward amount for the first Chrome full-chain exploit reported and double for any follow-up reports.
"While both of these large incentives have gone unclaimed, we are leaving the door open in 2024 for any researchers looking to take on these challenges," we're told.
[19]Google bug bounties inch closer to Microsoft's payouts
[20]Microsoft's bug bounty turns 10. Are these kinds of rewards making code more secure?
[21]Bug bounty hunters load up to stalk AI and fancy bagging big bucks
[22]DEF CON to set thousands of hackers loose on LLMs
Of course, the question with all of these bug bounties is: have they made software more secure?
The short answer is no, according to [23]Katie Moussouris , who played a key role in convincing Microsoft execs that Remond needed a vulnerability disclosure rewards program.
Moussouris, founder and CEO of Luta Security, in an [24]earlier interview with The Register that the rise of bug bounty platforms — and companies investing in cash payouts and related programs instead of developing secure software — is to blame.
"Because both of those are investments – it's not just about cash payments, it's about the work you have to do to actually fix the vulnerabilities," she said. ®
Get our [25]Tech Resources
[1] https://www.theregister.com/2023/06/24/google_bug_bounties_2022/
[2] https://www.theregister.com/2023/03/06/in_brief_security/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZfIwBUQwggdJBRC2hUDYpAAAAEU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://bughunters.google.com/about/rules/5429687846305792/bonus-awards-rules
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfIwBUQwggdJBRC2hUDYpAAAAEU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZfIwBUQwggdJBRC2hUDYpAAAAEU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://security.googleblog.com/2024/03/vulnerability-reward-program-2023-year.html
[8] https://security.googleblog.com/2023/05/new-android-google-device-VRP.html
[9] https://bughunters.google.com/about/rules/6618732618186752/google-mobile-vulnerability-reward-program-rules
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfIwBUQwggdJBRC2hUDYpAAAAEU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://www.theregister.com/2023/10/27/google_ai_bounty_hackerone/
[12] https://embracethered.com/blog/posts/2023/google-bard-data-exfiltration/
[13] https://www.landh.tech/blog/20240304-google-hack-50000/
[14] https://g.co/chrome/vrp
[15] https://security.googleblog.com/2022/09/use-after-freedom-miracleptr.html
[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZfIwBUQwggdJBRC2hUDYpAAAAEU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[17] https://g.co/chrome/vrp/#miracleptr-bypass-reward
[18] https://g.co/chrome/vrp/#full-chain-exploit-bonus
[19] https://www.theregister.com/2023/06/24/google_bug_bounties_2022/
[20] https://www.theregister.com/2023/11/22/microsofts_bug_bounty_moussouris/
[21] https://www.theregister.com/2023/10/27/google_ai_bounty_hackerone/
[22] https://www.theregister.com/2023/05/06/ai_hacking_defcon/
[23] https://www.theregister.com/2022/08/10/us_security_hiring/
[24] https://www.theregister.com/2023/11/22/microsofts_bug_bounty_moussouris/
[25] https://whitepapers.theregister.com/
The web goliath's 2023 total represents a slight dip compared to the [1]$12 million in bounties it paid the previous year. Hopefully this means more-secure products — not more researchers [2]turning to the dark side and making money selling exploits instead of disclosing them to vendors.
For comparison, consider that Microsoft paid out $13.8 million to 345 researchers between July 1, 2022, and June 30, 2023, according to Redmond's most recent rewards totals.
[3]
Google's 2023 highlights include newer reward categories, including finding flaws in its AI products and Android phone apps, plus a brand-new [4]Bonus Awards program that periodically pays out time-limited, extra rewards for specific vulnerability targets.
[5]
[6]
The single biggest reward last year hit $113,337, although the [7]year-in-review post doesn't say which program paid that amount and to whom.
Some of 2023's high-paying categories included Android VRP, which awarded more than $3.4 million to researchers who spotted Android device vulnerabilities. Google also last year [8]increased the max-reward amount to $15,000 for critical Android bugs, and launched a new [9]Mobile VRP that focuses on first-party Android apps.
[10]
Google also added Wear OS to the bounty program to encourage bug hunters to poke around in its smartwatches and other wearable tech. And in a live hack-a-thon for Wear OS and Android Automotive OS, bug bounty recipients received $70,000 for finding more than 20 critical vulnerabilities.
Google has also encouraged ethical hackers to [11]test for five categories of attacks in its AI products.
Last year, the Android juggernaut ran a bugSWAT live-hacking event targeting LLM products that produced 35 reports, totaling more than $87,000 rewards. These included [12]Hacking Google Bard - From Prompt Injection to Data Exfiltration and [13]We Hacked Google A.I. for $50,000 .
Chrome rewards
Jacobus describes 2023 as "a year of changes and experimentation" for Google's [14]Chrome VRP , which awarded $2.1 million to bug hunters who spotted 359 unique Chrome vulnerabilities in 2023.
Chrome calls its major new versions "milestones," and with milestone 116 passed in August, Google added [15]MiraclePtr — this is technology to prevent exploitation of use-after-free bugs — across all Chrome platforms.
[16]
This resulted in fewer vulnerability reports and lower rewards. However, the Chrome VRP has also added the [17]MiraclePtr Bypass Reward , which pays up to $100,115, to encourage researchers to try to find ways to bypass this security feature.
It also launched the [18]Full Chain Exploit Bonus , which pays triple the usual reward amount for the first Chrome full-chain exploit reported and double for any follow-up reports.
"While both of these large incentives have gone unclaimed, we are leaving the door open in 2024 for any researchers looking to take on these challenges," we're told.
[19]Google bug bounties inch closer to Microsoft's payouts
[20]Microsoft's bug bounty turns 10. Are these kinds of rewards making code more secure?
[21]Bug bounty hunters load up to stalk AI and fancy bagging big bucks
[22]DEF CON to set thousands of hackers loose on LLMs
Of course, the question with all of these bug bounties is: have they made software more secure?
The short answer is no, according to [23]Katie Moussouris , who played a key role in convincing Microsoft execs that Remond needed a vulnerability disclosure rewards program.
Moussouris, founder and CEO of Luta Security, in an [24]earlier interview with The Register that the rise of bug bounty platforms — and companies investing in cash payouts and related programs instead of developing secure software — is to blame.
"Because both of those are investments – it's not just about cash payments, it's about the work you have to do to actually fix the vulnerabilities," she said. ®
Get our [25]Tech Resources
[1] https://www.theregister.com/2023/06/24/google_bug_bounties_2022/
[2] https://www.theregister.com/2023/03/06/in_brief_security/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZfIwBUQwggdJBRC2hUDYpAAAAEU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://bughunters.google.com/about/rules/5429687846305792/bonus-awards-rules
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfIwBUQwggdJBRC2hUDYpAAAAEU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZfIwBUQwggdJBRC2hUDYpAAAAEU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://security.googleblog.com/2024/03/vulnerability-reward-program-2023-year.html
[8] https://security.googleblog.com/2023/05/new-android-google-device-VRP.html
[9] https://bughunters.google.com/about/rules/6618732618186752/google-mobile-vulnerability-reward-program-rules
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfIwBUQwggdJBRC2hUDYpAAAAEU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://www.theregister.com/2023/10/27/google_ai_bounty_hackerone/
[12] https://embracethered.com/blog/posts/2023/google-bard-data-exfiltration/
[13] https://www.landh.tech/blog/20240304-google-hack-50000/
[14] https://g.co/chrome/vrp
[15] https://security.googleblog.com/2022/09/use-after-freedom-miracleptr.html
[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZfIwBUQwggdJBRC2hUDYpAAAAEU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[17] https://g.co/chrome/vrp/#miracleptr-bypass-reward
[18] https://g.co/chrome/vrp/#full-chain-exploit-bonus
[19] https://www.theregister.com/2023/06/24/google_bug_bounties_2022/
[20] https://www.theregister.com/2023/11/22/microsofts_bug_bounty_moussouris/
[21] https://www.theregister.com/2023/10/27/google_ai_bounty_hackerone/
[22] https://www.theregister.com/2023/05/06/ai_hacking_defcon/
[23] https://www.theregister.com/2022/08/10/us_security_hiring/
[24] https://www.theregister.com/2023/11/22/microsofts_bug_bounty_moussouris/
[25] https://whitepapers.theregister.com/