Google paid more than $17 million to over 700 security researchers in various countries during 2025, according to an annual review of its Vulnerability Reward Program (VRP). This figure represents the highest annual amount in the program’s history and is more than 40% higher than in 2024, indicating Google’s continued reliance on the external research community to discover and address vulnerabilities in its products and services.
The 2025 results coincided with the program’s 15th anniversary. The program began in 2010 and has since undergone continuous expansion in the scope of its programs and reward mechanisms. Google said that participation by external researchers helps enhance the safety and security of its products and users, and also reflects the security research community’s acceptance of these programs.
A Dedicated Artificial Intelligence Track
During 2025, Google launched a dedicated artificial intelligence vulnerability rewards program, after this area had been organized under the Abuse VRP. Separating the two programs was accompanied by improvements to the rules, intended to provide researchers with greater clarity regarding the scope of testing and reward amounts.
The Chrome VRP also added reward categories for issues discovered in artificial intelligence features within Chrome. Artificial intelligence thus became an independent focus of Google’s vulnerability rewards program, in addition to being included within the scope of Chrome rewards.
Rewards for the OSV-SCALIBR Tool and Security Events
The company also launched a rewards program for updates to the open-source OSV-SCALIBR tool, a Google tool for discovering vulnerabilities in software dependencies. The program rewards contributors who provide new additions to the tool that help it inventory components, discover vulnerabilities, or detect secrets, thereby expanding its scanning capabilities. Google explained that user contributions had already helped it discover and address a number of secrets leaked internally.
In October, Google hosted the ESCAL8 conference in Mexico City as part of Cybersecurity Awareness Month. The conference included the init.g(mexico) workshop for students, the finals of the HACKCELER8 competition, and the Safer with Google seminar aimed at Mexican government officials.
bugSWAT Event Results
The bugSWAT event, a live hacking event for invited participants, held several editions during 2025. The announced results included:
- AI bugSWAT in Tokyo in April: more than 70 reports and rewards exceeding $400,000.
- Cloud bugSWAT in Sunnyvale in June: 130 reports and rewards totaling $1.6 million.
- bugSWAT in Las Vegas in August: 77 reports and rewards worth $380,000.
- bugSWAT Mexico at the ESCAL8 conference in Mexico City: 107 reports and total rewards of $566,000 at that time, covering artificial intelligence, Android, and Cloud.
Program Plans for 2026
Google plans to organize several bugSWAT events during 2026, along with holding a new edition of the ESCAL8 conference. The company said its broader goals are to prepare for emerging threats, adapt to changing technologies, and strengthen the security posture of its products and services in cooperation with the external research community.
Google notes that additional details about the Android, Abuse, AI, Cloud, Chrome, and OSS programs, including high-impact vulnerability reports and key research areas, are available in the expanded version of the review on the Security Engineering blog.