We ❤️ 🐜🐞🦗🦟🦋. {echo,{{{Google,Chrome,Android,Abuse,Mobile,OSS,Cloud}Vulnerability,Patch}Reward,VulnerabilityResearchGrants}Program}

📢 PSA for open-source bug hunters We are temporarily no longer accepting OSS VRP product vulnerability submissions. This does not impact OSS VRP supply chain reports, or any outstanding reports. As an alternative, we encourage you to find impact across our other VRP programs and submit there instead, or pursue the Patch Rewards Program. Why is this happening? This pause is due to a significant rise in automated submissions, the vast majority of which are not valid. We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027. bughunters.google.com/about/…
8
34
319
55,994
Introducing PageBreak, an agentic vulnerability discovery tool using deterministic validation to achieve a near-zero false positive rate. How it works: blog.google/security/agentic… For real-world vulnerabilities PageBreak has discovered 👇 bughunters.google.com/blog/p…
23
196
1,206
96,372
ESCAL8, Google’s annual flagship security conference, is coming to Singapore in October 2026, with a particular focus on AI Agents! 🇸🇬 Check out our blog post to see what's planned in the three main segments of the conference: bugSWAT, Hackceler8, and init.g() 👇 bughunters.google.com/blog/e…
10
92
7,477
📢📢📢 Attention bug hunters! Want to know more about how brutecat found a vulnerability in Google’s internal APIs, bypassing authorization to exploit the GFile library to gain access to internal filesystems and storage? If yes, check out his blog post 👇 bughunters.google.com/blog/b…
9
83
550
45,950
📢 Tracking our VRP rules just got easier! We are now mirroring our VRP rules and help articles directly on GitHub. Perfect for automating your workflows and tracking changes. 👇 github.com/google/bughunters
6
33
317
20,754
Teamwork makes the dream work 🙌 Google Bug Hunters now supports sharing the recognition (and splitting the financial reward) for reports you have submitted, but were researched and created in collaboration with other researchers. Details 👇 bughunters.google.com/about/…
5
9
110
10,285
Interested in crypto 🔒? Check out our latest post which analyzes recent results published by Anthropic and argues that these advances, while significant, do not signal the downfall of cryptography. bughunters.google.com/blog/m…
6
3
41
5,633
Check out Tomas' post and article on hacking Google using Git integrations. One of these reports even won him Most Valuable Hacker (MVH) at Google's bugSWAT event in Vegas last year!
The written version of my BSides Riga and @bsidesvilnius talks is up: exploiting git integrations in cloud services, with four bugs I found in GCP (Looker, Dataform), including the one that won me MVH. nopnop.pro/2026/06/17/exploi…
16
150
15,489
"brutecat is super talented", "luckily I'm not oncall ;)", "incredible" These are all real quotes from Googlers after seeing this blog post. Amazing work @brutecat, thank you for sharing!
Hacking Google with A.I. for $500,000 brutecat.com/r/hacking-googl…
1
27
571
38,592
📢 PSA for security researchers! In our latest post, we're taking a closer look at how Google Spark (which was recently launched) works, ways to approach bug hunting in Spark, and how to distinguish high-impact vulnerabilities from expected system behavior 👇 bughunters.google.com/blog/s…
3
9
109
10,560
📣Blast from the past📣 This post takes us back to a flaw discovered in 2010: while technology has advanced, the general story of how the flaw was detected is still a great example of effectively identifying and remediating a security issue. bughunters.google.com/blog/b…
2
4
34
3,910
📢 More on Google's approach to post-quantum cryptography 🔐 This time, we're taking a closer look at digital signatures and the complex challenges they present, and discussing the opinionated paths we are taking at Google in this space. bughunters.google.com/blog/n…
7
43
4,690
More on passkeys 🔐! This time we are focusing on storage options, in particular the differences between using a password manager vs. a hardware security key to store your credentials, and why you might choose one option over the other. bughunters.google.com/blog/h…
2
19
2,835
In April 2026, we held the latest edition of bugSWAT (our live event for security researchers) in Seoul, South Korea. For more information on this edition's focus, its impact & winners, as well as bugSWAT in general, see 👇 bughunters.google.com/blog/b…
2
13
78
8,001
📣📢 Calling all Android and Chrome bug hunters 🧑‍💻🔎! We're updating our Android & Chrome VRP programs to ensure we can continue to reward the most challenging and impactful vulnerabilities researchers find in our products. For details, 👇 bughunters.google.com/blog/e…
22
34
207
150,757
Our Google Cloud VRP researchers don't want to miss this! 🔥 Check out Omer's (@omer_asfu) cross-tenant bucket squatting research.
I achieved a cross-tenant #RCE in #GoogleCloud simply by abusing predictable bucket names. 🪣 In my latest research for @FocalSecurity, I look into "Bucket Squatting" - a cross-tenant attack that landed me 3 critical vulnerabilities in GCP. Here is how it works:
2
11
103
14,260
📢📢📢 Attention bug hunters! The Google VRP is updating its reward model, with a focus on the impact of vulnerabilities and the sensitivity of the data involved. To this end, we're introducing two dimensions: Information Tiers and Action Criticality. 👀👇 bughunters.google.com/blog/s…
9
37
241
21,201
Ever wondered how passkeys 🔐 work, and how they improve on classic passwords 🔤? For more details, see our latest post, and you'll also learn what makes passkeys particularly resistant against phishing 🐟. bughunters.google.com/blog/p…
1
4
39
11,490