Skip to main content
  1. Home
  2. Computing
  3. Android
  4. Mobile
  5. News

Google dished out $6.5M in bug bounties in 2019 with one payout worth $201K

Add as a preferred source on Google

Google has revealed that it paid out a total of $6.5 million in 2019 to people who found critical flaws in its software.

The cash payments are part of Google’s bug bounty program, which, since its launch in 2010, has handed out a total of $21 million.

Recommended Videos

All of the major tech companies operate similar bug bounty programs in an effort to keep their software safe and secure. The programs invite so-called “ethical hackers,” also known as white-hat hackers, to examine software code in search of vulnerabilities that a more malicious hacker might exploit, with potentially damaging consequences for the company involved. That’s why the likes of Google, Apple, and Microsoft are prepared to pay big money for the discovery of serious software flaws.

In 2019, Google’s single biggest payment was a cool $201,000, though the company declined to offer any details about the nature of the vulnerability.

In all, 461 researchers received bug bounty payments from Google in 2019. The company said last year’s total payout of $6.5 million doubled its previous highest annual payout, adding that those who received the rewards donated a total of $500,000 to charity — five times more than any previous year when the bounty program has been running.

Part of the reason the numbers are rising is that Google has been gradually expanding the scope of its program to cover additional products, including Chrome, Android, and popular third-party apps on Google Play. It’s also added abuse-related weaknesses where someone finds a way to manipulate, say, the rating scores of listings on tools such as Google Maps. It’s also upped the baseline reward amounts, leading to higher payouts for researchers who report critical vulnerabilities.

There’s certainly some serious money to be made for those with the skills to track down the bugs. Toward the end of last year, for example, Google announced it was increasing its top payout to a staggering $1 million for the discovery of a specific Android vulnerability. It even includes the possibility of a 50% bonus that would push the payout to $1.5 million.

In 2018, California-based Google revealed how an 18-year-old researcher collected $36,000 from its bug bounty program after discovering a vulnerability that could have allowed a hacker to make changes to the company’s internal computer systems.

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
WhatsApp can now open and edit PDFs without making you download them first
Adobe Acrobat is adding built-in viewing and annotation tools for PDFs shared through WhatsApp on larger screens
Text, Person, Aircraft

Adobe is making PDF attachments much less annoying in WhatsApp. Its new Acrobat integration lets you open a PDF and mark it up without downloading the file or leaving the conversation.

The feature is available today through WhatsApp Web and the Windows app. The headline comes with an important caveat, though. This isn’t full PDF editing. You can review and annotate a document, but you can’t rewrite its original text or rearrange the layout.

Read more
Substack now lets you check if a post was written by AI
A new Pangram-powered scanner lets you check posts, notes, and replies for signs of AI writing.
Video playing on Substack.

Substack is giving readers a way to check whether the post they're reading was written by a human or by a chatbot. The company has partnered with AI-detection firm Pangram to introduce new tools that will let users scan posts, notes, and replies for AI-generated text. CEO Chris Best introduced the features in a post titled "Against Claudefishing," his term for content that leans on AI while presenting itself as human work.

How the scanning tool works

Read more
China’s AI talent shortage has tech giants recruiting teenagers
Forget campus recruiting, china's biggest tech firms are betting on teenage coders.
Artificial Intelligence

A 13-year-old boy in Hangzhou has already won national AI competitions and built a following of more than 136,000 people online, all while his dad tries to figure out how to guide him through a field that barely existed when he himself was growing up. That family's situation, first reported by Rest of World, says a lot about where China's tech industry is heading right now.

Companies used to wait for graduates to walk through the door. Now they're reaching further back, first to undergrads, and increasingly to teenagers, hoping to spot rare talent before anyone else gets to them.

Read more