The milestone represents a 40% increase compared to 2024 and coincides with the 15th anniversary of Google’s long-running bug bounty initiative.
The record-breaking payouts highlight the growing importance of crowdsourced security as cyber threats become more sophisticated.
In total, over 700 security researchers worldwide received rewards for responsibly disclosing vulnerabilities across Google’s ecosystem, helping the company proactively mitigate risks before they could be exploited in the wild.
A key development in 2025 was Google’s strategic shift toward securing artificial intelligence systems.
Recognizing the rapid adoption and evolving threat landscape surrounding AI technologies, the company introduced a dedicated AI Vulnerability Reward Program.
This new initiative provides clearer testing guidelines and defined reward structures specifically for AI-related findings, which were previously handled under the broader Abuse VRP.
The expansion reflects increasing concerns around AI misuse, model manipulation, and prompt injection attacks.
Google also extended its Chrome VRP to include vulnerabilities tied to AI-powered features, such as Gemini integrations, signaling a deeper focus on securing AI-driven user experiences.
Beyond AI, Google continued to strengthen its investment in open-source security and collaborative research.
The company launched a patch reward program for OSV-SCALIBR, an open-source tool designed to detect vulnerabilities in software dependencies.
Security researchers contributing innovative scanning plugins were eligible for rewards, with external contributions already helping Google identify and remediate internal security issues, including leaked secrets.
Live hacking events remained a cornerstone of Google’s community engagement strategy.
Through its invite-only bugSWAT program, the company brought together top researchers to identify high-impact vulnerabilities in real-world environments.
These events not only accelerated vulnerability discovery but also fostered collaboration between Google engineers and the global security community.
Several bugSWAT events stood out in 2025:
These events demonstrate the effectiveness of live, collaborative testing in uncovering complex vulnerabilities across diverse attack surfaces.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google
The post Google Bug Bounty Payouts Reach Record $17 Million in 2025 appeared first on Cyber Security News.
Resident Evil Requiem players were sad to see the Merchant left out of Leon's latest…
It looks like Marathon won’t be left behind anytime soon, as Bungie has confirmed it…
A new weekend has arrived, and today, you can save big on Yakuza Kiwami 3…
A new weekend has arrived, and today, you can save big on Yakuza Kiwami 3…
Microsoft Defender triggered widespread false positive alerts after a faulty security update caused it to…
Developer Arc System Works has confirmed that Hulk and Black Panther have joined the roster…
This website uses cookies.