Early access: the directory is still filling out, and every rating here is a reported experience.
GO

Self-hosted security programme

Google

Google runs Bug Hunters, its own reporting and reward platform, covering Google, Chrome, Android and the open source it maintains. There is no profile to claim here.

Rewards are set by a panel against a published table, and the amount turns on report quality as much as severity: a clear reproduction routinely lands higher than the same bug described loosely.

Direct How to report
In-house Triage
Panel Reward decisions
Bug Hunters Where credit lands

Featured write-up

The Program with Massive Surface Area, Fair Triage, and Great Scope Alignment

“Majorly I participate in Google VRP mostly as a casual and daily user rather than doing dedicated, aggressive bug hunting. Most of the security flaws I have reported came from normal day to day usage of Google products rather than active deep scanning. The sheer size of the target surface means anyone with a security mindset can spot imp…”

SS SSP
Read the write-up ★★★★★ · August 2026

Getting credit

Report to Google, claim it here

Credit publishes in Google’s own advisories, often months after the report. We index those, so it is waiting for you, including recognitions that carry no CVE and appear nowhere else.

NR Unrated
Google Vulnerability Reward Program
Google Independent · self-hosted $100–$250,000
2 more reviews needed for a grade
Reported practices
+ Clear, current policy 1 report
+ Engages on the technical detail 1 report
+ Consistent decisions 1 report
+ Clear, honest scope 1 report
+ Respectful & professional 1 report
Slow to pay 1 report

Found a vulnerability?

Google runs its own vulnerability reporting process. Here are your two ways to report it. We recommend the first.

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Reviews

1 published
The Program with Massive Surface Area, Fair Triage, and Great Scope Alignment
positive

Majorly I participate in Google VRP mostly as a casual and daily user rather than doing dedicated, aggressive bug hunting. Most of the security flaws I have reported came from normal day to day usage of Google products rather than active deep scanning. The sheer size of the target surface means anyone with a security mindset can spot impactful vulnerabilities, while experts still have room to dig into obscure endpoints and under-explored domains. The triage team is technically solid, supportive, and fair when aligning scope, though response times can occasionally slow down due to the recent heavy influxes of AI based low quality submissions from others. Overall, it remains a highly transparent, well-coordinated program that I readily recommend. Experiences vary across sub-categories like Chrome VRP or Android VRP, but the main Google VRP track covering web products, AI, and Cloud is consistently smooth to work with.

via Direct / email 1st reply Within 3 days resubmit yes recommends yes skill Novice
+ Clear, current policy + Clear, honest scope + Consistent decisions + Engages on the technical detail + Respectful & professional − Slow to pay
SSP · Aug 6, 2026 · Share ↗ 1 helpful
0 comments

Log in to comment