Early access: this site has moved to bugrater.com.
GO

Self-hosted security programme

Google

Google runs Bug Hunters, its own reporting and reward platform, covering Google, Chrome, Android and the open source it maintains. There is no profile to claim here.

Rewards are set by a panel against a published table, and the amount turns on report quality as much as severity: a clear reproduction routinely lands higher than the same bug described loosely.

Direct How to report
In-house Triage
Panel Reward decisions
Bug Hunters Where credit lands

Featured write-up

The Program with Massive Surface Area, Fair Triage, and Great Scope Alignment

“Majorly I participate in Google VRP mostly as a casual and daily user rather than doing dedicated, aggressive bug hunting. Most of the security flaws I have reported came from normal day to day usage of Google products rather than active deep scanning. The sheer size of the target surface means anyone with a security mindset can spot imp…”

SS SSP
Read the write-up ★★★★★ · August 2026

Getting credit

Report to Google, claim it here

Credit publishes in Google’s own advisories, often months after the report. We index those, so it is waiting for you, including recognitions that carry no CVE and appear nowhere else.

NR Unrated
Google
Google HackerOne
3 more reviews needed for a grade

Found a vulnerability?

Google runs its own vulnerability reporting process. Here are your two ways to report it. We recommend the first.

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Program metrics HackerOne · published

HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 22 Sep 2026.

What it pays, by severity

Critical no reports on record
High no reports on record
Medium no reports on record
Low no reports on record

Intake & responsiveness · last 90 days

Reports received
not published
in 90 days
Resolved
not published
all time
Participants
0
hunters engaged
Response efficiency
not published
HackerOne’s figure
SLA misses
0
targets missed

Getting in the door

Open to submit. Nothing HackerOne publishes stands between a hunter and a first report here.

Over 33 days (18 snapshots): no change on the figures worth watching.

Reviews

0 published

No reviews yet.

Be the first to review

Program profile HackerOne · imported

Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 15 Sep 2026.

Organize the world’s information and make it universally accessible and useful.