Google's Vulnerability Rewards Program (VRP) marked its 15th anniversary in 2025 by distributing a record $17 million in rewards to more than 700 security researchers worldwide. This annual figure represents a substantial increase in payouts and researcher participation.
The program experienced notable expansion throughout the year. A significant development was the introduction of a dedicated AI VRP, signaling Google's increased focus on the security of its artificial intelligence initiatives.
Furthermore, the Chrome VRP saw its reward categories broadened to encompass AI features integrated within the Chrome browser. This move acknowledges the growing importance of AI's role in web browsing security.
In addition to these advancements, Google launched a new patch rewards program. This initiative specifically targets contributions related to the OSV-SCALIBR tool, encouraging the development and improvement of security patching mechanisms.
The record-breaking year for the VRP underscores Google's ongoing commitment to fostering a collaborative security ecosystem. By incentivizing researchers, the company aims to proactively identify and address potential vulnerabilities across its diverse range of products and services.
The global reach of the program is highlighted by the participation of over 700 researchers from various international locations. This broad engagement allows for a diverse range of perspectives and expertise to be applied to security testing.
The sustained growth of the VRP over its 15-year history demonstrates its effectiveness as a mechanism for enhancing product security. The program's evolution, particularly its adaptation to emerging fields like AI, reflects the dynamic nature of cybersecurity threats and the need for continuous innovation in defense strategies.
The introduction of the patch rewards program for OSV-SCALIBR suggests a strategic effort to improve the efficiency and effectiveness of software updates and security fixes. This focus on post-vulnerability remediation is a critical component of a comprehensive security posture.






