Skip to main content

Google paid its highest-ever bug bounty last year

Someone made a lot of money discovering vulnerabilities in Google products in 2022, the company has revealed.

The search engine giant recently disclosed the results of its Vulnerability Reward Program, a bug bounty campaign that rewards ethical hackers who discover major flaws in its products and disclose them responsibly instead of giving hackers an opportunity to abuse them with malware

In total, the company paid out more than $12 million for roughly 2,900 vulnerabilities over the course of 2022.

Flaws in Android, Chrome, and ChromeOS

One unique report stands out in Google's report - a hacker discovered an exploit chain, involving five separate vulnerabilities in Android - CVE-2022-20427, CVE-2022-20428, CVE-2022-20454, CVE-2022-20459, CVE-2022-20460. Google decided the exploit chain warranted a $605,000 reward. 

The person who discovered the exploit chain goes by the alias gzobqq, BleepingComputer reported, adding that the same person earned $157,000 in 2021, as well, for a critical exploit chain in Android. Both these exploit chains were the highest bug bounty in Android at their respective times. 

Looking at Android specifically, last year Google paid out $4.8 million in rewards. The three most active hackers reported 200, 150, and 100 bugs, respectively.

Furthermore, the company paid out almost $500,000 for 700 reports done through the Android Chipset Security Reward Program. ACSRP is a private bug bounty program reserved only for Android chipset manufacturers. 

For 363 flaws discovered in Chrome, and 110 in ChromeOS, Google paid out $4 million.

Most major tech companies operate bug bounty programs, as they are a great way to incentivize the wider cybersecurity community to participate in the strengthening of the world’s most popular software. 

In August 2022, Microsoft reported paying out $13.7 million in rewards, to 330 security researchers across 46 countries. The largest award, under the Hyper-V Bounty Program, was $200,000, the company added, while the average award was approximately $12,000.

Apple, on the other hand, said it paid out $20 million via its bug bounty program in 2022, with the average reward in the product category being $40,000.

Via: BleepingComputer



Comments

Popular posts from this blog

Garmin's new radar-equipped tail light will keep you safe on your e-bike

Garmin's Varia bike radars are some of the most popular pieces of cycling tech around – and now the company has delivered its first rearview radar to have been specially designed for some of the best e-Bikes .   Garmin's Varia range mounts to the back of your bike and broadcasts a radar signal behind you, so you can get visual and audible alerts when something's overtaking you. Even better, the new Varia eRTL615 plugs directly into most e-bikes, with no battery required. Because the catchily-named Varia eRTL615 is also a tail light, it'll also make sure you're visible to other vehicles too, promising to emit a flashing or solid light that's visible from up to a mile away in daylight. To connect Garmin's new radar tail light to your e-bike, you'll need to pick the right Garmin adapter cable (which isn't included). You can buy power cables compatible with Bosch, Shimano, or USB-A terminals or connections, with more info on those available on Garmin...

Revolution Software is using their own AI technology to remake Broken Sword

TechRadar Gaming is reporting live from Gamescom 2023 on the latest and greatest developments in gaming and hardware. Revolution Software announced at Gamescom 2023 that Broken Sword would be coming back, with Broken Sword - The Shadow of the Templars getting a full remake while a sixth title in the series is coming in the future too, under the title Broken Sword - Parzival’s Stone .  Speaking to TRG ahead of the announcement, Cecil talked about the studio’s plans for a Broken Sword remake and the sixth title in the series. Cecil is a larger-than-life character, who is able to talk about the studio’s plans with enthusiasm. It even carries a pocketful of stones to illustrate the plans for Parzival’s Stone , but he also talks about how Broken Sword - The Shadow of the Templars would be using AI to upscale.  Cecil wasn’t shy about the studio’s use of AI technology, but he gave a fairly robust explanation of why the game was using it. The AI technology will be used to upda...

Hackers steal passwords, emails from hookup websites

Two gay hookup websites have been breached with sensitive and personal user data stolen and sold online, new reports have claimed. The databases, which are now being sold on dark web forums, were taken from platforms called TruckerSucker, and CityJerks. They contain enough personally identifiable information to engage in identity theft , such as usernames and passwords, email addresses, profile pictures, sexual preferences, birth dates, postal addresses, IP addresses, and bios. The passwords are encrypted, but according to TechCrunch, the algorithm is “weak” and could be broken by a more persistent hacker. The silent treatment HaveIBeenPwned founder Troy Hunt, who was tipped off on the leak, described the incident as a “typical forum breach, albeit with super sensitive content.”  However the content includes more than just identity data, as there are also messages users exchanged, including arranging meetings and describing their sexual preferences.  In total, more than...