Google shelled out $10 million in bug bounties in 2023
Google handed out $10 million in total last year for finding security flaws in its products.
Stay updated with breaking news from Google Vulnerability Reward Program. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
Google handed out $10 million in total last year for finding security flaws in its products.
A big year for bug bounties at Google
Google Cloud has fixed a flaw impacting Kubernetes that could allow an attacker to escalate their privileges.
The Asset Key Thief vulnerability gave rise to multiple potential attack scenarios that could have impacted thousands of Google Cloud users, but has now been safely fixed.
Engineers write off GC abuse because Spectre broke everything anyway Share Copy In early November, a developer contributing to Google's open-source Chromium project reported a problem with Oilpan, the garbage collector for the browser's Blink rendering engine: it can be used to break a memory defense known as address space layout randomization (ASLR). About two weeks later, Google software security engineer Chris Palmer marked the bug "WontFix" because Google has resigned itself to the fact that ASLR can't be saved – Spectre and Spectre-like processor-level flaws can defeat it anywa...