Getting credit
Report to Google, claim it here
Credit publishes in Google’s own advisories, often months after the report. We index those, so it is waiting for you — including recognitions that carry no CVE and appear nowhere else.
Google runs Bug Hunters, its own reporting and reward platform, covering Google, Chrome, Android and the open source it maintains. There is no profile to claim here.
Rewards are set by a panel against a published table, and the amount turns on report quality as much as severity — a clear reproduction routinely lands higher than the same bug described loosely.
Getting credit
Credit publishes in Google’s own advisories, often months after the report. We index those, so it is waiting for you — including recognitions that carry no CVE and appear nowhere else.
Found a vulnerability?
Google runs its own vulnerability reporting process. Here are your two ways to report it — we recommend the first.
Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.