This blog post describes how we used AI to help us rewrite a C library (giflib) to Rust to mitigate memory safety vulnerabilities.
This post analyzes results published by Anthropic and argues that these recent advances do not signal the downfall of cryptography.
Gemini Spark brings a persistent agent to the Gemini App. Learn how to approach security testing for this new paradigm and focus on high-impact bugs.
This blog post takes us back to 2010, retracing and incident where a statistical anomaly led to the discovery of a subtle flaw in the way we were using a security-critical library.
This blog post explores how Google thinks about the development and deployment of quantum-safe digital signatures.
Passkeys can be combined with hardware security keys to implement advanced security features when a particularly robust security strategy is required.
In this blog post, we'll take a look at what makes bugSWAT events valuable in general, and focus on the latest edition in Seoul, which took place in April 2026.
We are announcing changes to the Chrome & Android Vulnerability Reward Programs (VRP) which take effect immediately and are focused on adjusting our reward amounts and bonuses to reflect the types of reports and bug categories that provide the most value to security today.
We are evolving our reward model to reflect the changing security landscape by introducing two new dimensions to our model: Information Tiers and Action Criticality.
Find out more about how passkeys, which are designed to replace passwords, work and which advantages they bring.
Read about our updates to the OSS VRP rules which are designed to help us filter out low-quality reports and focus on real-world impact.
This blog post takes you through the 2025 highlights across the assorted VRPs at Google.
This post takes a look at how Gemini and other agents created by Google mitigate URL-based data exfiltration attacks.
Find out how the FIDO alliances's Hybrid transport architecture was expanded to support authentication in the offline world, increasing reliability and unlocking many new use cases.
This post highlights how Hybrid transport is being extended to support generic JSON messages – paving the way for a host of new, secure authentication and credential use cases.
This blog post details the results of the joint security review of the Intel Trust Domain Extensions (TDX) 1.5 Google performed together with Intel.
Find out more about how passkeys can be used across devices using a mechanism called Hybrid transport.
Based on the FIDO specification, online authentication has undergone a significant transformation in the past years, moving beyond simple passwords to more secure, phishing-resistant methods.
Check this post to find out what a Task Injection attack is, how this type of attack differs from Prompt Injection, and how it is particularly relevant to AI agents designed for a wide range of actions and tasks.
In this post, we're sharing our assessment of the Quantum Key Distribution (QKD) technology and explaining why we believe PQC is the more mature and scalable solution for Google's needs.
This blog post presents two initiatives that demonstrate two ways Google shares security work with the industry: Contributing to the Secure Web Application Guidelines Community Group in W3C, and introducing auto-CSP in Angular.
ESCAL8 is focused on collaboration, knowledge-sharing, and a commitment to a safer digital world. See our blog post for an overview of the four main segments of the 2025 edition of ESCAL8.
Looking back at two years of AI bug bounties at Google, and announcing our new AI Vulnerability Reward Program!
See how we're updating the Cloud VRP rewards structure to increase transparency, improve consistency, and reduce ambiguity.
We're announcing an update to how we evaluate report quality across the Google, Cloud, AI, and Abuse Vulnerability Reward Programs (VRPs) to ensure more consistent reward outcomes, and make it straightforward to qualify for the exceptional reward bonus.
This blog shares a detailed overview of the L1TF vulnerability, a CPU vulnerability on some Intel CPUs (Skylake and older), and explains how it could be exploited and what mitigation strategies are possible.
Rendering untrusted web content is fraught with security risks. Learn how SafeContentFrame, a new TypeScript library, offers a robust solution for isolating web content and protecting against threats like XSS and side-channel attacks.
Find out more about last year’s ESCAL8 conference, and also see what we have planned for ESCAL8 2025.
Check out this blog post for more on the inaugural Cloud-focused bugSWAT, hosted by the Cloud VRP, and how events like this help boost Google's security posture in close collaboration with external researchers.
This blog post describes the journey of discovering a VM escape bug with the goal of demystifying the security research process and demonstrating how persistence and pivoting can lead to achieving successful exploitation.
Curious to hear about our experience exploiting Retbleed (a security vulnerability affecting modern CPUs)? Then check out this post to see how we pushed the boundaries of Retbleed exploitation and understand more about the security implications of this exploit for modern computing systems.
Check out our new Patch Rewards Program for OSV-SCALIBR, offering financial incentives for providing novel OSV-SCALIBR plugins for inventory, vulnerability, or secret detection.
The HTML specification has been updated to escape '' in attributes to prevent mutation XSS (mXSS) vulnerabilities. This post details the reasoning behind this change and explains why this update improves security.
This blog post presents one of the events we regularly host to complement our VRP program – bugSWAT, with a particular focus on our latest, AI-related event in Tokyo!
The Android & Google Device VRP now offers a $1,000 reward to researchers who include an AutoRepro test with their vulnerability report! Check out our blog post for more details.
This blog post takes you through the 2024 highlights across the assorted VRPs at Google.
This blog post covers the full details of EntrySign, the AMD Zen microcode signature validation vulnerability recently discovered by the Google Security team.
Join us as we take a closer look at the technical details of how we identified the root causes for TT violations in two flagship rollouts: Gmail and AppSheet.
Learn more about how Google has created and deployed a high-assurance web framework that almost completely eliminates exploitable web vulnerabilities.
This blog post takes you through everything you need to know about the Patch Rewards Program, including our newly introduced focus on memory safety (including reward multipliers!), recently increased reward amounts, and lots more!