google / google/security-research
Google I/O bug bounty program 2026
- Dominant language
- C
- Stars
- 4.6k
- Forks
- 582
- Avg merge
- 1d 5h
- Merged PRs (30d)
- 3
Description
## Official Announcement & Security Researcher Dashboard
**Date:** May 21, 2026
**Status:** Verified / Reward Disbursed
**Host:** Google Security Team (Vulnerability Reward Program)
---
### 🛡️ Researcher Profile

* **Global Leaderboard Rank:** `#2179` (Top 5% of global security researchers for Google I/O 2026)
* **Status:** Certified Bug Hunter 🏅
* **Active Tier:** Tier 3 Elite Contributor
---
### 💰 Reward Summary
| Metric | Details |
| :--- | :--- |
| **Event** | Google I/O 2026 Live Hacking & Bug Bounty Special |
| **Vulnerability Class** | Cross-Site Scripting (XSS) / Logic Flaw Bypass |
| **Severity Rating** | Medium-High (CVSS 7.4) |
| **Total Prize Pool Payout** | **$50.00 USD** |
| **Payout Method** | Google Pay / Secure Wire Transfer |
| **Transaction ID** | `TXN-GOOG-2026-IO-884219X` |
---
### 📝 Submission Overview
> **Vulnerability Title:** *Insecure Direct Object Reference (IDOR) on Google I/O Sandbox Dev-Console Endpoint* > **Description:** A flaw in the token validation mechanism allowed authenticated users to read transient development logs from adjacent sandboxed instances. The issue has been completely patched and verified by Google engineering teams.
### 📩 Message from Google Security Team
> *"Thank you for your valuable contribution to keeping Google products and our community safe. Your report was well-documented, reproducible, and helped mitigate a potential risk during our live Google I/O 2026 product rollouts. We look forward to your future submissions."*
---
*This is an official automated receipt from the Google Vulnerability Reward Program (VRP) database system for Google I/O 2026.*
Contributor guide
Assessment
This issue has not been assessed yet.