Security Engineering Blog

Google's goal is to make it easier for ourselves, and the rest of the world, to ship secure products. Our blog is intended to share ways in which we make the Internet, as a whole, safer, and what that journey entails. · nguồn: rss


Scaling Memory Safety: AI-Assisted Rewrites of C/C++ Dependencies to Rust

2026-08-24T00:00:00.000Z · Security Engineering Blog

This blog post describes how we used AI to help us rewrite a C library (giflib) to Rust to mitigate memory safety vulnerabilities.

More Cryptanalysis Makes Us All Safer

2026-08-10T00:00:00.000Z · Security Engineering Blog

This post analyzes results published by Anthropic and argues that these recent advances do not signal the downfall of cryptography.

Bug Hunting on Gemini Spark

2026-06-05T00:00:00.000Z · Security Engineering Blog

Gemini Spark brings a persistent agent to the Gemini App. Learn how to approach security testing for this new paradigm and focus on high-impact bugs.

Bit Rot Doesn't Always Increase Entropy – A Story from the Archives

2026-06-04T00:00:00.000Z · Security Engineering Blog

This blog post takes us back to 2010, retracing and incident where a statistical anomaly led to the discovery of a subtle flaw in the way we were using a security-critical library.

Where to Go Next with Quantum-Safe Certificates

2026-06-01T00:00:00.000Z · Security Engineering Blog

This blog post explores how Google thinks about the development and deployment of quantum-safe digital signatures.

A Look at Hardware Security Keys for Passkeys

2026-05-27T00:00:00.000Z · Security Engineering Blog

Passkeys can be combined with hardware security keys to implement advanced security features when a particularly robust security strategy is required.

bugSWAT in Seoul – April 2026

2026-05-11T00:00:00.000Z · Security Engineering Blog

In this blog post, we'll take a look at what makes bugSWAT events valuable in general, and focus on the latest edition in Seoul, which took place in April 2026.

Evolving the Android & Chrome VRPs for the AI Era

2026-04-30T00:00:00.000Z · Security Engineering Blog

We are announcing changes to the Chrome & Android Vulnerability Reward Programs (VRP) which take effect immediately and are focused on adjusting our reward amounts and bonuses to reflect the types of reports and bug categories that provide the most value to security today.

Standardizing Rewards in Google VRP: Introducing Information Tiers and Action Criticality

2026-04-08T00:00:00.000Z · Security Engineering Blog

We are evolving our reward model to reflect the changing security landscape by introducing two new dimensions to our model: Information Tiers and Action Criticality.

Passkeys are Your New Best Friend

2026-03-30T00:00:00.000Z · Security Engineering Blog

Find out more about how passkeys, which are designed to replace passwords, work and which advantages they bring.

Streamlining Google’s OSS VRP: Key Rule Updates

2026-03-19T00:00:00.000Z · Security Engineering Blog

Read about our updates to the OSS VRP rules which are designed to help us filter out low-quality reports and focus on real-world impact.

Google VRPs in Review – 2025

2026-03-11T00:00:00.000Z · Security Engineering Blog

This blog post takes you through the 2025 highlights across the assorted VRPs at Google.

Mitigating URL-based Exfiltration in Gemini

2026-03-09T00:00:00.000Z · Security Engineering Blog

This post takes a look at how Gemini and other agents created by Google mitigate URL-based data exfiltration attacks.

Hybrid Transport Goes Offline!

2026-03-04T00:00:00.000Z · Security Engineering Blog

Find out how the FIDO alliances's Hybrid transport architecture was expanded to support authentication in the offline world, increasing reliability and unlocking many new use cases.

Hybrid Protocol: The JSON Upgrade

2026-02-23T00:00:00.000Z · Security Engineering Blog

This post highlights how Hybrid transport is being extended to support generic JSON messages – paving the way for a host of new, secure authentication and credential use cases.

Strengthening the Foundation: A Joint Security Review of Intel TDX 1.5

2026-02-10T00:00:00.000Z · Security Engineering Blog

This blog post details the results of the joint security review of the Intel Trust Domain Extensions (TDX) 1.5 Google performed together with Intel.

A Beginners Guide: Cross-Device Passkeys

2026-02-03T00:00:00.000Z · Security Engineering Blog

Find out more about how passkeys can be used across devices using a mechanism called Hybrid transport.

The Evolution of FIDO Experiences on Android

2026-01-27T00:00:00.000Z · Security Engineering Blog

Based on the FIDO specification, online authentication has undergone a significant transformation in the past years, moving beyond simple passwords to more secure, phishing-resistant methods.

Task Injection – Exploiting agency of autonomous AI agents

2025-12-11T00:00:00.000Z · Security Engineering Blog

Check this post to find out what a Task Injection attack is, how this type of attack differs from Prompt Injection, and how it is particularly relevant to AI agents designed for a wide range of actions and tasks.

Google's Commitment to a Quantum-Safe Future: Why PQC is Google's Path forward and not QKD

2025-12-01T00:00:00.000Z · Security Engineering Blog

In this post, we're sharing our assessment of the Quantum Key Distribution (QKD) technology and explaining why we believe PQC is the more mature and scalable solution for Google's needs.

Effortless Web Security: Secure by Design in the Wild

2025-11-14T00:00:00.000Z · Security Engineering Blog

This blog post presents two initiatives that demonstrate two ways Google shares security work with the industry: Contributing to the Secure Web Application Guidelines Community Group in W3C, and introducing auto-CSP in Angular.

ESCAL8 2025: Gathering Cybersecurity Expertise in Mexico City

2025-11-07T00:00:00.000Z · Security Engineering Blog

ESCAL8 is focused on collaboration, knowledge-sharing, and a commitment to a safer digital world. See our blog post for an overview of the four main segments of the 2025 edition of ESCAL8.

Announcing Google’s New AI Vulnerability Reward Program!

2025-10-06T00:00:00.000Z · Security Engineering Blog

Looking back at two years of AI bug bounties at Google, and announcing our new AI Vulnerability Reward Program!

Google Cloud VRP: Enhancing Transparency and Impact in Our Rewards Program

2025-09-25T00:00:00.000Z · Security Engineering Blog

See how we're updating the Cloud VRP rewards structure to increase transparency, improve consistency, and reduce ambiguity.

Level Up Your Reports: Introducing Our Updated Report Quality Framework

2025-09-22T00:00:00.000Z · Security Engineering Blog

We're announcing an update to how we evaluate report quality across the Google, Cloud, AI, and Abuse Vulnerability Reward Programs (VRPs) to ensure more consistent reward outcomes, and make it straightforward to qualify for the exceptional reward bonus.

Project Rain:L1TF

2025-09-19T00:00:00.000Z · Security Engineering Blog

This blog shares a detailed overview of the L1TF vulnerability, a CPU vulnerability on some Intel CPUs (Skylake and older), and explains how it could be exploited and what mitigation strategies are possible.

Beyond Sandbox Domains: Rendering Untrusted Web Content with SafeContentFrame

2025-09-18T00:00:00.000Z · Security Engineering Blog

Rendering untrusted web content is fraught with security risks. Learn how SafeContentFrame, a new TypeScript library, offers a robust solution for isolating web content and protecting against threats like XSS and side-channel attacks.

ESCAL8 de Google: ¡Hacking, Héroes y Horizontes en la Ciudad de México! (ESCAL8 is coming to Mexico!)

2025-09-17T00:00:00.000Z · Security Engineering Blog

Find out more about last year’s ESCAL8 conference, and also see what we have planned for ESCAL8 2025.

Hardening Google Cloud: Insights from the latest Cloud VRP bugSWAT

2025-09-10T00:00:00.000Z · Security Engineering Blog

Check out this blog post for more on the inaugural Cloud-focused bugSWAT, hosted by the Cloud VRP, and how events like this help boost Google's security posture in close collaboration with external researchers.

A Fuzzy Escape - A tale of vulnerability research on hypervisors

2025-08-18T00:00:00.000Z · Security Engineering Blog

This blog post describes the journey of discovering a VM escape bug with the goal of demystifying the security research process and demonstrating how persistence and pivoting can lead to achieving successful exploitation.

Exploiting Retbleed in the real world

2025-08-07T00:00:00.000Z · Security Engineering Blog

Curious to hear about our experience exploiting Retbleed (a security vulnerability affecting modern CPUs)? Then check out this post to see how we pushed the boundaries of Retbleed exploitation and understand more about the security implications of this exploit for modern computing systems.

New Patch Rewards Program for OSV-SCALIBR

2025-08-07T00:00:00.000Z · Security Engineering Blog

Check out our new Patch Rewards Program for OSV-SCALIBR, offering financial incentives for providing novel OSV-SCALIBR plugins for inventory, vulnerability, or secret detection.

Escaping '<' and '>' in attributes – how it helps protect against mutation XSS

2025-06-12T00:00:00.000Z · Security Engineering Blog

The HTML specification has been updated to escape '' in attributes to prevent mutation XSS (mXSS) vulnerabilities. This post details the reasoning behind this change and explains why this update improves security.

AI bugSWAT in Tokyo & 2025 Hacker Roadshow

2025-06-03T00:00:00.000Z · Security Engineering Blog

This blog post presents one of the events we regularly host to complement our VRP program – bugSWAT, with a particular focus on our latest, AI-related event in Tokyo!

Android VRP Announces AutoRepro – $1,000 bonus for eligible submissions!

2025-03-26T00:00:00.000Z · Security Engineering Blog

The Android & Google Device VRP now offers a $1,000 reward to researchers who include an AutoRepro test with their vulnerability report! Check out our blog post for more details.

Google VRPs in Review – 2024

2025-03-17T00:00:00.000Z · Security Engineering Blog

This blog post takes you through the 2024 highlights across the assorted VRPs at Google.

Zen and the Art of Microcode Hacking

2025-03-05T00:00:00.000Z · Security Engineering Blog

This blog post covers the full details of EntrySign, the AMD Zen microcode signature validation vulnerability recently discovered by the Google Security team.

A Deep Dive into JS Trusted Types Violations

2025-02-27T00:00:00.000Z · Security Engineering Blog

Join us as we take a closer look at the technical details of how we identified the root causes for TT violations in two flagship rollouts: Gmail and AppSheet.

Secure by Design: Google's Blueprint for a High-Assurance Web Framework

2025-02-04T00:00:00.000Z · Security Engineering Blog

Learn more about how Google has created and deployed a high-assurance web framework that almost completely eliminates exploitable web vulnerabilities.

Level Up Your Open Source Karma (And Your Wallet) by Improving Security

2025-01-21T00:00:00.000Z · Security Engineering Blog

This blog post takes you through everything you need to know about the Patch Rewards Program, including our newly introduced focus on memory safety (including reward multipliers!), recently increased reward amounts, and lots more!