Google VRP (Google Bug Hunters)

331 posts

Google VRP (Google Bug Hunters) banner
Google VRP (Google Bug Hunters)

Google VRP (Google Bug Hunters)

@GoogleVRP

We ❤️ 🐜🐞🦗🦟🦋. {echo,{{{Google,Chrome,Android,Abuse,Mobile,OSS,Cloud}Vulnerability,Patch}Reward,VulnerabilityResearchGrants}Program}

Beigetreten Mart 2018
0 Folgt40.6K Follower
Google VRP (Google Bug Hunters)
📢 Open source security researchers, take note: we've updated the OSS VRP rules! We're emphasizing the need for actionable reports and verifiable reproduction steps – to allow us to focus on critical threats with real-world impact. For more details 👇 bughunters.google.com/blog/ossvrp-ru…
English
0
9
63
4K
Google VRP (Google Bug Hunters)
📣📣📣 Hot off the press: 2025 highlights of Google's vulnerability reward programs! Notably, we awarded an all-time high of over $17 million in rewards 💰 and kicked off the dedicated AI VRP 🤖. Thank you to our incredible bug hunting community 🧑‍💻🧑‍💻🧑‍💻!!! bughunters.google.com/blog/google-vr…
English
3
9
83
10.1K
Google VRP (Google Bug Hunters)
📢 Interested in AI and agent security at Google🛡️? This post looks at how we mitigated the risk of URL-based data exfiltration through provenance checks and sanitization – effectively blocking a prompt injection-based exploitation vector. bughunters.google.com/blog/mitigatin…
English
4
19
108
18.1K
Google VRP (Google Bug Hunters)
🔒 Want to move beyond passwords? Check out this beginner's guide to Cross-Device Passkeys! Learn how "Hybrid transport" uses QR codes and Bluetooth to let you sign in securely on any device – even public ones – without ever sharing your private keys. bughunters.google.com/blog/passkeys
English
0
18
79
6.2K
Google VRP (Google Bug Hunters)
Want to see what elite security research looks like? 🌟 @omer_asfu, one of Google Cloud VRP's best, dropped a cross-tenant finding: CVE-2025-13292 (nvd.nist.gov/vuln/detail/CV…)
OmerAF@omer_asfu

👼GatewayToHeaven (CVE-2025-13292). I discovered a cross-tenant vulnerability in @GoogleCloud's #Apigee, allowing me to access other organizations' data (and sometimes even plaintext JWTs of end users). Below is the full breakdown of the exploit chain⛓️

English
2
41
279
23.7K
Google VRP (Google Bug Hunters)
Interested in Android and authentication 🤖 🔒? Our latest post takes a look at how online authentication on Android evolved from simple passwords to more secure methods, and highlights the role of FIDO (Fast Identity Online) Alliance specifications. bughunters.google.com/blog/fido
English
4
17
85
6.9K
Google VRP (Google Bug Hunters)
📢📢📢 Our Patch Rewards Program rules were updated to explicitly encourage batched submissions, and place every Google-filed OSS vulnerability explicitly into scope (thanks for your feedback). Interested in getting rewarded for your awesome OSS security work? g.co/prp
English
0
29
136
20.8K
Google VRP (Google Bug Hunters)
We're LIVE from the Google Cybersecurity Engineering Center in Malaga! ⚡🛡️ The init.g sessions are kicking off, we're excited to meet the talent that will redefine the future of cybersecurity. Learning, networking, and lots of good hacking. init.g(malaga) { return SUCCESS; }
Google VRP (Google Bug Hunters) tweet mediaGoogle VRP (Google Bug Hunters) tweet mediaGoogle VRP (Google Bug Hunters) tweet media
English
4
11
65
6.4K