ReconDock By Kdairatchi
Go To ReconDock
MyRepo
MyRepo
  • Pastebin Services
  • Awesome Ai Talk
  • Bug Bounty Testing, Techniques, and Tools
  • Cybersources
  • Targets
  • Bug checklist
  • Bug Bounty Platforms
  • Awesome Bug Bounty Tips Awesome
    • CVE Exploits and PoC Collection
  • ============ Awesome Bugs
    • Awesome One-liner Bug Bounty
  • Awesome CS Courses
  • Awesome Cyber Co
  • Awesome Dev
  • Awesome Free Certs
  • Awesome Git
  • Awesome Github
  • Awesome Go
  • Awesome Interviews
  • Awesome Keys
  • Awesome Mac OpenSource
  • Awesome Mac
  • Awesome Python
    • Awesome Tool
  • Awesome-Selfhosted
    • Awesome Hacker Search Engines
  • Awesome Shell
  • Awesome Shodan Search Queries
  • Awesome Static Website Services Awesome
  • Awesome Vulnerable Applications
  • Awesome WAF
  • Awesome First PR Opportunities
  • Awesome-Bugbounty-Writeups
  • Awesome-web3-Security awesome
  • Bug-Bounty
  • CTF Tools
  • Awesome Blockchain Bug Bounty
  • Awesome Bug Bounty
  • awesome-design-systems
  • Awesome Google VRP Writeups
  • Web Scraping
  • awesome
  • bug-bounty-reference
  • the-book-of-secret-knowledge
  • APACHE
  • AWS
  • AZURE
  • CISCO
  • CLOUDFLARE
  • Cross Origin Resource Sharing (CORS)
  • CRLF Injection || HTTP Response Splitting
  • CSV Injection
  • Content Injection
  • CRLF Injection || HTTP Response Splitting
  • JENKINS
  • JIRA
  • LFI
  • OR
  • PostgreSQL Environment Variable Manipulation Vulnerability
  • RCE
  • Recon
  • SSRF
  • Proof OF Concept (POC): SharePoint Vulnerability Detection
  • Template Injection
  • WORDPRESS
  • XSLT Injection
  • XSS
  • XXE
  • Books
  • Firebase Subdomain Enumeration & PoC Testing
  • SQLI
  • Special Tools
  • Account Takeover
  • Authentication
  • Broken Link Hijacking
  • Business Logic Errors
  • Default Credentials
  • Email Spoofing
  • ExposedAPIkeys
  • ForgotPasswordFunctionality
  • JWT Vulnerabilities
  • OWASPTestingChecklist1
  • Tabnabbing
  • Web Cache Poisoning
  • Wordpress Endpoints to look
  • lfi_vulnerble_targets
  • (LFI)passwrd
  • LostSec
  • POCS
    • CVES
      • CVE-2021-36873
      • BreadcrumbsSQL_Injection_cve_2024
      • CVE-2024-0195
      • CVE-2024-29269 Exploit
  • 403-ByPass
  • Chat-bot_xss_payloads
  • burp
    • Match & Replace
    • Zap
  • cloudflare-waf-bypass
  • infosec
    • Customize the bash shell environments
    • automation
    • Website Ideas
  • 2FA bypass
  • Account Takeover
  • OWASP Web Application Security Testing Checklist
  • Projects
  • OWASP Top Ten
  • links
  • Bug Bounty Builder ¯\(ツ)/¯
  • Awesome
    • AllAboutBugBounty: All about bug bounty (bypasses, payloads, and etc)
  • Cheatsheets
  • Checklists
    • Here’s a clear, step by step breakdown of commands, tools, and objectives for each section in your Web Security Testing Guide (WSTG). Each test includes easy to follow commands, explanations, and examples where applicable.
  • Dorks
  • Scripts
  • Loads
  • OWASP
    • Checklist
  • ai
    • Ai Best for Information and Coding
  • Medium Recent Writeups
  • 🌟 Useful Extensions for Bug Bounty Hunting 🌟
  • Customize the bash shell environments
  • Fabric
    • Test Application Platform Configuration
  • Docker
  • Git auto
  • Bug Bounty Beginner's Roadmap
  • Methodology 2025
    • Advanced Recon Methodology
Powered by GitBook
On this page
  • Contributing:
  • Writeups:
  • 2024:
  • 2023:
  • 2022:
  • 2021:
  • 2020:
  • 2019:
  • 2018:
  • 2017:
  • 2016:
  • 2015:
  • 2014:
  • 2013:
  • Unknown Date:

Awesome Google VRP Writeups

Previousawesome-design-systemsNextWeb Scraping

Last updated 4 months ago

🐛 A list of writeups from the Google VRP Bug Bounty program

*writeups: not just writeups

Follow on Twitter to get new writeups straigt into your feed!

Contributing:

If you know of any writeups/videos not listed in this repository, feel free to open a Pull Request.

To add a new writeup, simply add a new line to writeups.csv:

[YYYY-MM-DD],[bounty],[title],[url],[author-name],[author-url],[type],false,?

If a value is not available, write ?. The value of type can either be blog or video. If any of the fields include a ,, please wrap the value in quotes. Please keep the last two fields set to false and ?. The automation will modify these fields. If available, set author-url to the author's Twitter URL, so the automation can @mention the author.

Writeups:

2024:

  • [Nov 11 - $???] by

  • [Sep 25 - $4,837] by

  • [Sep 19 - $3,133.7] by

  • [Sep 19 - $4,133.7] by

  • [Aug 26 - $500] by

  • [Aug 24 - $1,337] by

  • [Aug 16 - $1,337] by

  • [Aug 13 - $???] by

  • [Aug 04 - $???] by

  • [Aug 02 - $1,000] by

  • [Aug 02 - $???] by

  • [Aug 01 - $3,133.7] by

  • [Aug 01 - $14,008.7] by

  • [Jul 31 - $???] by

  • [Jul 26 - $???] by

  • [Jul 24 - $???] by

  • [Apr 15 - $7,500] by

  • [Mar 23 - $4,133.7] by

  • [Mar 04 - $50,000] by

2023:

2022:

2021:

2020:

2019:

2018:

2017:

2016:

2015:

2014:

2013:

Unknown Date:

[Nov 14 - $10,000] by

[Nov 14 - $???] by

[Nov 02 - $???] by

[Oct 19 - $???] by

[Sep 18 - $???] by

[Sep 11 - $???] by

[Aug 18 - $18,833.7] by

[Jul 22 - $???] by

[Jul 07 - $0] by

[Jul 03 - $500] by

[Jun 30 - $???] by

[Jun 23 - $1,337] by

[Jun 21 - $4,133.7] by

[Jun 11 - $7,500] by

[Jun 09 - $6,000] by

[Apr 20 - $???] by

[Apr 18 - $???] by

[Apr 13 - $500] by

[Mar 31 - $0] by

[Mar 28 - $???] by

[Mar 18 - $???] by

[Mar 13 - $5,000] by

[Mar 11 - $1,837] by

[Feb 10 - $500] by

[Feb 09 - $???] by

[Feb 07 - $0] by

[Feb 05 - $???] by

[Jan 22 - $???] by

[Jan 15 - $3,133.7] by

[Jan 13 - $3,133.7] by

[Jan 12 - $6,000] by

[Jan 12 - $3,133.7] by

[Jan 06 - $2,337] by

[Dec 26 - $107,500] by

[Dec 26 - $20,000] by

[Nov 30 - $1,337] by

[Nov 10 - $70,000] by

[Sep 22 - $0] by

[Sep 16 - $???] by

[Sep 06 - $3,133.7] by

[Jul 26 - $8,133.7] by

[Jun 09 - $???] by

[Apr 23 - $1,337] by

[Mar 25 - $0] by

[Mar 19 - $10,000] by

[Mar 08 - $???] by

[Feb 20 - $3,133.7] by

[Feb 06 - $2,674] by

[Feb 06 - $1,337] by

[Feb 02 - $???] by

[Dec 30 - $5,000] by

[Dec 28 - $3,133.7] by

[Dec 25 - $???] by

[Dec 21 - $5,000] by

[Dec 05 - $6,267.4] by

[Nov 21 - $???] by

[Nov 17 - $10,401.1] by

[Nov 11 - $1,337] by

[Oct 24 - $7,500] by

[Oct 18 - $???] by

[Oct 14 - $0] by

[Oct 11 - $0] by

[Oct 08 - $25,401.1] by

[Sep 28 - $???] by

[Sep 10 - $1,337] by

[Sep 06 - $4,133.7] by

[Aug 24 - $???] by

[Aug 23 - $???] by

[Jul 13 - $???] by

[Jul 08 - $0] by

[Jun 25 - $???] by

[Jun 16 - $???] by

[Jun 13 - $3,133.7] by

[Jun 09 - $500] by

[May 31 - $10,000] by

[May 17 - $???] by

[May 16 - $5,000] by

[May 05 - $???] by

[Apr 29 - $???] by

[Apr 21 - $???] by

[Apr 20 - $???] by

[Apr 13 - $1,337] by

[Apr 09 - $31,337] by

[Apr 06 - $31,337] by

[Apr 05 - $6,000] by

[Apr 02 - $100] by

[Mar 22 - $5,000] by

[Mar 21 - $???] by

[Mar 17 - $165,174] by

[Mar 11 - $3,133.7] by

[Mar 08 - $0] by

[Mar 08 - $5,000] by

[Feb 28 - $???] by

[Feb 16 - $0] by

[Jan 31 - $5,000] by

[Jan 27 - $???] by

[Jan 25 - $5,000] by

[Jan 18 - $1,337] by

[Jan 11 - $5,000] by

[Jan 08 - $3,133.7] by

[Dec 30 - $???] by

[Dec 27 - $???] by

[Dec 22 - $0] by

[Dec 21 - $0] by

[Dec 19 - $0] by

[Nov 12 - $31,337] by

[Oct 27 - $6,337] by

[Oct 26 - $0] by

[Oct 15 - $???] by

[Oct 08 - $30,000] by

[Oct 01 - $5,000] by

[Sep 29 - $???] by

[Sep 20 - $500] by

[Sep 10 - $15,000] by

[Sep 08 - $10,000] by

[Sep 07 - $1,337] by

[Aug 26 - $???] by

[Aug 25 - $1,337] by

[Aug 22 - $???] by

[Aug 19 - $???] by

[Aug 18 - $???] by

[Aug 18 - $???] by

[Aug 17 - $???] by

[Aug 15 - $???] by

[Jul 31 - $4,133.7] by

[Jul 28 - $1,337] by

[Jul 17 - $5,000] by

[Jul 14 - $6,267.4] by

[Jun 15 - $3,133.7] by

[Jun 06 - $500] by

[Jun 04 - $???] by

[Jun 04 - $???] by

[May 21 - $31,337] by

[May 10 - $???] by

[May 08 - $4,133.7] by

[May 07 - $3,133.7] by

[May 07 - $???] by

[May 03 - $???] by

[Apr 30 - $6,267.4] by

[Mar 27 - $3,133.7] by

[Mar 11 - $100,000] by

[Mar 10 - $3,133.7] by

[Mar 08 - $6,000] by

[Mar 07 - $5,000] by

[Jan 12 - $???] by

[Dec 30 - $3,133.7] by

[Dec 19 - $???] by

[Dec 16 - $???] by

[Dec 15 - $5,000] by

[Dec 15 - $5,000] by

[Dec 15 - $5,000] by

[Dec 09 - $???] by

[Nov 29 - $1,337] by

[Nov 18 - $???] by

[Oct 01 - $5,000] by

[Sep 09 - $???] by

[Aug 31 - $36,337] by

[Jul 20 - $13,337] by

[Jul 10 - $???] by

[May 21 - $13,337] by

[Apr 27 - $0] by

[Apr 23 - $???] by

[Mar 31 - $???] by

[Mar 29 - $0] by

[Mar 26 - $3,133.7] by

[Feb 12 - $???] by

[Jan 31 - $???] by

[Jan 30 - $7,500] by

[Jan 25 - $3,133.7] by

[Jan 18 - $10,000] by

[Dec 12 - $???] by

[Dec 11 - $???] by

[Dec 05 - $500] by

[Nov 25 - $???] by

[Nov 19 - $???] by

[Nov 14 - $58,837] by

[Nov 11 - $7,500] by

[Oct 04 - $???] by

[Sep 05 - $???] by

[Aug 22 - $???] by

[May 25 - $???] by

[Apr 06 - $5,000] by

[Mar 31 - $5,000] by

[Mar 28 - $???] by

[Mar 07 - $13,337] by

[Feb 24 - $13,337] by

[Feb 19 - $???] by

[Feb 14 - $7,500] by

[Oct 30 - $15,600] by

[Jun 21 - $???] by

[Jun 08 - $???] by

[Mar 09 - $5,000] by

[Mar 01 - $???] by

[Feb 26 - $3,133.7] by

[Jan 04 - $???] by

[Nov 29 - $???] by

[Oct 09 - $6,000] by

[Aug 26 - $500] by

[Feb 28 - $???] by

[Dec 08 - $???] by

[Oct 29 - $???] by

[Jun 26 - $3,133.7] by

[Oct 31 - $5,000] by

[Oct 26 - $1,337] by

[Aug 13 - $???] by

[Jan 10 - $???] by

[Sep 15 - $3,133.7] by

[Jul 08 - $???] by

[??? - $5,000] by

[??? - $???] by

[??? - $???] by

[??? - $???] by

[??? - $???] by

[??? - $???] by

[??? - $3,133.7] by

[??? - $???] by

[??? - $???] by

[??? - $???] by

[??? - $???] by

[??? - $???] by

@gvrp_writeups
Release-Drafter To google/accompanist Compromise: VRP Writeup
*
Adnan Khan
XS-Search on Google Photos
*
NDevTK
Office Editing for Docs Sheets & Slides leak
*
NDevTK
Using YouTube to steal your files
*
Lyra Rebane
[$500] How I was able to give verification badge to any YouTube channel and bypass needed requirements
*
Vojtech Cekal
Exploiting Sandbox Escape Vulnerability in Apigee PythonScript Policy
*
Nikita Markevich
Kicking Off the Apigee Security Series: Discovering Rhino’s Blind Spot
*
Nikita Markevich
ArtiPACKED: Hacking Giants Through a Race Condition in GitHub Actions Artifacts
*
Yaron Avital
How I Got Critical P2 Bug on Google
*
Kazi Hashibur Rahman
Chromium infra leak
*
NDevTK
Supply Chain Attack on Chromium-BiDi and Puppeteer via GitHub Cache Poisoning
*
inspector-ambitious
idx.google.com XSS
*
NDevTK
Android web attack surface
*
NDevTK
Escalating Privileges in Google Cloud via Open Groups
*
Thomas Elling
Leaking All Users Google Drive Files
*
Cameron Vincent
ConfusedFunction: A Privilege Escalation Vulnerability Impacting GCP Cloud Functions
*
Liv Matan
An Obscure Actions Workflow Vulnerability in Google’s Flank
*
Adnan Khan
Hacking the Giant: How I Discovered Google’s Vulnerability and Hall of Fame Recognition
*
Henry N. Caga
We Hacked Google A.I. for $50,000
*
Lupin
Uncovering a crazy privilege escalation from Chrome extensions
*
Derin Eryilmaz
Google VRP -[IDOR] Deleted Victim Data & Leaked
*
Gilang Romadon
ApatchMe - Authenticated Stored XSS Vulnerability in AWS and GCP Apache Airflow Services
*
Tenable
Google Cloud Vertex AI - Data Exfiltration Vulnerability Fixed in Generative AI Studio
*
Johann Rehberger
How i found an Stored XSS on Google Books
*
Sokol Çavdarbasha
GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure
*
Ofir Balassiano
Google Extensions
*
NDevTK
Hijacking Cloud CI/CD Systems for Fun and Profit
*
Divyanshu
A Journey Into Hacking Google Search Appliance
*
DEVCORE
Hunting for Nginx Alias Traversals in the wild
*
Hakai Offensive Security
Server-side Template Injection Leading to RCE on Google VRP
*
mizzleneupane
Insecure sandbox on Colaboratory
*
NDevTK
Unveiling a Critical Authentication Bypass Vulnerability in Google Cloud API Gateway
*
Securing Bits
googlesource.com access_token leak
*
NDevTK
XSS in GMAIL Dynamic Email (AMP for Email)
*
asdqw3
GhostToken – Exploiting GCP application infrastructure to create invisible, unremovable trojan app on Google accounts
*
Astrix Security
How Material Security Uncovered a Vulnerability in the Gmail API
*
Material Security
Remote Code Execution Vulnerability in Google They Are Not Willing To Fix
*
Giraffe Security
Unveiling the Secrets: My Journey of Hacking Google’s OSS
*
7h3h4ckv157
The curl quirk that exposed Burp Suite & Google Chrome
*
Paul Mutton
Exploiting aCropalypse: Recovering Truncated PNGs
*
David Buchanan
The Time I Hacked Google’s Manual Actions Database
*
Tom Anthony
CCAI XSS
*
NDevTK
Information disclosure or GDPR breach? A Google tale…
*
Luke Berner
Broken Access Control can create Asset library whereas role access is billing + IDOR | Google Ads
*
Gilang Romadon
Google Meet Flaw — Join Any Organisation Call (Not an 0day but still acts as 0day) — Refused by GoogleVRP
*
Basavaraj Banakar
I was able to see likes count even though it was hidden by the victim | YouTube App 16.15.35
*
R ando
How i was able to get critical bug on google by get full access on [Google Cloud BI Hackathon]
*
Orwa Atyat
XSS using postMessage in Google Cloud Theia notebooks [Google VRP]
*
Sreeram KL
Bypassing authorization in Google Cloud Workstations [Google VRP]
*
Sivanesh Ashok
SSH key injection in Google Cloud Compute Engine [Google VRP]
*
Sivanesh Ashok
Client-Side SSRF to Google Cloud Project Takeover [Google VRP]
*
Sreeram KL
Identity-Aware Proxy Misconfiguration- Google Cloud Vulnerability
*
Borna Nematzadeh
Turning Google smart speakers into wiretaps for $100k
*
Matt Kunze
Few bugs in the google cloud shell
*
Obmi
The space creators can still see the members of the space, even after they have been removed from the space.
*
Vivek M
Accidental $70k Google Pixel Lock Screen Bypass
*
David Schütz
Exploiting Distroless Images
*
Daniel Teixeira
Cloning internal Google repos for fun and… info?
*
Luke Berner
IDOR leads to removing members from any Google Chat Space.
*
Vivek M
Google Play and DevSite XSS
*
NDevTK
How to download eBooks from Google Play Store without paying for them
*
Yess
Launching a Supply Chain Counterattack Against Google and OpenSSF
*
Alan Cao
Clipboard hazard with Google Sheets
*
Imre Rad
System environment variables leak on Google Chrome - Microsoft Edge and Opera
*
Maciej Pulikowski
Container Escape to Shadow Admin: GKE Autopilot Vulnerabilities
*
Unit 42
Send a Email and get kicked out of Google Groups - A Feature that almost broke Google Groups
*
Sriram
Auth Bypass in Google Assistant
*
David Schütz
Auth Bypass in com.google.android.googlequicksearchbox
*
David Schütz
How I Was Able To Track You Around The Globe!
*
Nikhil Kaushik
Email storage leaking ticket-attachment
*
NDevTK
RCE in Google Cloud Dataflow
*
Mike Brancato
How I Saved Christmas For Google!
*
Nikhil Kaushik
Google Cloud Shell XSS
*
NDevTK
SSRF vulnerability in AppSheet - Google VRP
*
David Nechuta
Becoming A Super Admin In Someone Elses Gsuite Organization And Taking It Over
*
Cameron Vincent
Reacting to myself finding an SSRF vulnerability in Google Cloud
*
David Schütz
GOOGLE VRP BUG BOUNTY: /etc/environment local variables exfiltrated on Linux Google Earth Pro desktop app
*
Omar Espino
A 7500$ Google sites IDOR
*
r0ckin
The Speckle Umbrella story — part 2
*
Imre Rad
GOOGLE VRP N/A: Arbitrary local file read (macOS) via <a> tag and null byte (%00) in Google Earth Pro Desktop app
*
Omar Espino
Hacking YouTube With MP4
*
Florian Mathieu
4 Weird Google VRP Bugs in 40 Minutes - Hacktivity 2021
*
David Schütz
Google Extensible Service Proxy v1 - CWE-287 Improper Authentication
*
Imre Rad
Bypassing GCP Org Policy with Custom Metadata
*
Kat Traxler
2 CSRF 1 IDOR on Google Marketing Platform
*
Apapedulimu
The Nomulus rift
*
Imre Rad
Hey Google ! - Delete my Data Properly — #GoogleVRP
*
Sriram Kesavan
Unencrypted HTTP Links to Google Scholar in Search
*
David Schütz
IDOR on clientauthconfig.googleapis.com
*
David Schütz
Google Compute Engine (GCE) VM takeover via DHCP flood
*
Imre Rad
Story of Google Hall of Fame and Private program bounty worth $$$$
*
Basavaraj Banakar
Privilege escalation on https://dialogflow.cloud.google.com
*
lalka
Author spoofing in Google Colaboratory
*
Zohar Shacha
AppCache's forgotten tales
*
Luan Herrera
Clickjacking in Nearby Devices Dashboard
*
David Schütz
Auth Bypass in https://nearbydevices-pa.googleapis.com
*
David Schütz
How I Hacked Google App Engine: Anatomy of a Java Bytecode Exploit
*
Robert Grosse
De-anonymising Anonymous Animals in Google Workspace
*
David Schütz
IDOR leads to how many likes that was hidden | Youtube
*
R Ando
Auth Bypass in Google Workspace Real Time Collaboration
*
David Schütz
Google Photos : Theft of Database & Arbitrary Files Android Vulnerability
*
Rahul Kankrale
Explaining the exploit to $31,337 Google Cloud blind SSRF
*
Bug Bounty Reports Explained
$31,337 Google Cloud blind SSRF + HANDS-ON labs
*
Bug Bounty Reports Explained
I Built a TV That Plays All of Your Private YouTube Videos
*
David Schütz
Play a game, get Subscribed to my channel - YouTube Clickjacking Bug
*
Sriram Kesavan
File System Access API - vulnerabilities
*
Maciej Pulikowski
How I made it to Google HOF?
*
Sudhanshu Rajbhar
Hacking into Google's Network for $133,337
*
LiveOverflow
How I Get Blind XSS At Google With Dork (First Bounty and HOF )
*
Rio Mulyadi Pulungan
Google VRP N/A: SSRF Bypass with Quadzero in Google Cloud Monitoring
*
Omar Espino
$5,000 YouTube IDOR
*
Bug Bounty Reports Explained
Metadata service MITM allows root privilege escalation (EKS / GKE)
*
Etienne Champetier
Dropping a shell in Google’s Cloud SQL (the speckle-umbrella story)
*
Imre Rad
Hacking YouTube to watch private videos?
*
Tech Raj
Hijacking Google Drive Files (documents, photo & video) through Google Docs Sharing
*
santuySec
This YouTube Backend API Leaks Private Videos
*
Hussein Nasser
The Embedded YouTube Player Told Me What You Were Watching (and more)
*
David Schütz
Stealing Your Private YouTube Videos, One Frame at a Time
*
David Schütz
Blind XSS in Google Analytics Admin Panel — $3133.70
*
Ashish Dhone
Getting my first Google VRP trophies
*
Imre Rad
Google VRP Hijacking Google Docs Screenshots
*
Sreeram KL
SSTI in Google Maps
*
Zohar Shacha
remote code execution when open a project in android studio that google refused to fix
*
houjingyi
Google VRP – Sandboxed RCE as root on Apigee API proxies
*
Omar Espino
31k$ SSRF in Google Cloud Monitoring led to metadata exposure
*
David Nechuta
The YouTube bug that allowed unlisted uploads to any channel
*
Ryan Kovatch
Deciphering Google’s mysterious ‘batchexecute’ system
*
Ryan Kovatch
CVE-2020-15157 "ContainerDrip" Write-up
*
Brad Geesaman
The mass CSRFing of *.google.com/* products.
*
Missoum Said
Google bug bounty: XSS to Cloud Shell instance takeover (RCE as root) - $5,000 USD
*
Omar Espino
Public Bucket Allowed Access to Images on Upcoming Google Cloud Blog Posts
*
Thomas Orlita
How I earned $500 from Google - Flaw in Authentication
*
Hemant Patidar
Universal XSS in Android WebView (CVE-2020-6506)
*
Alesandro Ortiz
XSS->Fix->Bypass: 10000$ bounty in Google Maps
*
Zohar Shacha
My first bug in google and how i got CSRF token for victim account rather than bypass it
*
Oday Alhalbe
Auth bypass: Leaking Google Cloud service accounts and projects
*
Ezequiel Pereira
How I Tracked Your Mother: Tracking Waze drivers using UI elements
*
Peter Gasper
The Short tale of two bugs on Google Cloud Product— Google VRP (Resolved)
*
Sriram Kesavan
The Confused Mailman: Sending SPF and DMARC passing mail as any Gmail or G Suite customer
*
Allison Husain
How to contact Google SRE: Dropping a shell in Cloud SQL
*
Ezequiel Pereira
Three More Google Cloud Shell Bugs Explained
*
David Dworken
Firebase Cloud Messaging Service Takeover: A small research that led to 30k$+ in bounties
*
Abss
How I was able to send Authentic Emails as others - Google VRP (Resolved)
*
Sriram Kesavan
Script Gadgets! Google Docs XSS Vulnerability Walkthrough
*
LiveOverflow
Authorization bypass in Google’s ticketing system (Google-GUTS)
*
Zohar Shacha
Idor in google product
*
baluz
Hunting postMessage Vulnerabilities
*
Gary O'leary-Steele
SMTP Injection in Gsuite
*
Zohar Shacha
How i earned $500 from google by change one character .
*
Oday Alhalbe
Privilege Escalation in Google Cloud Platform's OS Login
*
Chris Moberly
Three Privilege Escalation Bugs in Google Cloud Platform’s OS Login
*
initstring
RCE in Google Cloud Deployment Manager
*
Ezequiel Pereira
Bypassing Firebase authorization to create custom goo.gl subdomains
*
Thomas Orlita
Bypass XSS filter using HTML Escape
*
Syahri Ramadan
DOM-Based XSS at accounts.google.com by Google Voice Extension
*
Missoum Said
Google Acquisition XSS (Apigee)
*
TnMch
DOM XSS in Gmail with a little help from Chrome
*
Enguerran Gillier
Researching Polymorphic Images for XSS on Google Scholar
*
Lorenzo Stella
$3133.7 Google Bug Bounty Writeup- XSS Vulnerability!
*
Pethuraj M
$100k Hacking Prize - Security Bugs in Google Cloud Platform
*
LiveOverflow
Cookie Tossing to RCE on Google Cloud JupyterLab
*
s1r1us
The unexpected Google wide domain check bypass
*
David Schütz
Google Ads Self-XSS & Html Injection $5000
*
Syahri Ramadan
Information Disclosure Vulnerability in the Google Cloud Speech-to-Text API
*
Dan Maas
How did I earn $3133.70 from Google Translator? (XSS)
*
Beri Bey
SSRF in Google Cloud Platform StackDriver
*
Ron Chan
4 Google Cloud Shell bugs explained
*
Wouter ter Maat
The File uploading CSRF in Google Cloud Shell Editor
*
Obmi
The oauth token hijacking in Google Cloud Shell Editor
*
Obmi
The XSS ( type II ) in Google Cloud Shell Editor
*
Obmi
BlackAlps 2019: Google Bug Hunters
*
Eduardo Vela Nava
Writeup for the 2019 Google Cloud Platform VRP Prize!
*
Missoum Said
XSS in GMail’s AMP4Email via DOM Clobbering
*
Michał Bentkowski
Google Paid Me to Talk About a Security Issue!
*
LiveOverflow
Combination of techniques lead to DOM Based XSS in Google
*
Sasi Levi
$36k Google App Engine RCE
*
Ezequiel Pereira
Into the Borg – SSRF inside Google production network
*
Enguerran Gillier
Gsuite Hangouts Chat 5k IDOR
*
Cameron Vincent
Google Bug Bounty: LFI on Production Servers in “springboard.google.com” – $13,337 USD
*
Omar Espino
Broken Access: Posting to Google private groups through any user in the group
*
Elber Andre
Best Of Google VRP 2018 | nullcon Goa 2019
*
Daniel Stelter-Gliese
XSS on Google Search - Sanitizing HTML in The Client?
*
LiveOverflow
Inserting arbitrary files into anyone’s Google Earth Projects Archive
*
Thomas Orlita
How I could have hijacked a victim’s YouTube notifications!
*
Yash Sodha
Hacking YouTube for #fun and #profit
*
Alexandru Coltuneac
LFI in Apigee portals
*
Wouter ter Maat
$7.5k Google Cloud Platform organization issue
*
Ezequiel Pereira
How I abused 2FA to maintain persistence after a password change (Google, Microsoft, Instagram, Cloudflare, etc)
*
Luke Berner
$10k host header
*
Ezequiel Pereira
XSSing Google Code-in thanks to improperly escaped JSON data
*
Thomas Orlita
Clickjacking DOM XSS on Google.org
*
Thomas Orlita
Billion Laugh Attack in https://sites.google.com
*
Antonio Sanso
XSS in Google's Acquisition
*
Abartan Dhakal
XS-Searching Google’s bug tracker to find out vulnerable source code
*
Luan Herrera
Google Cloud Platform vulnerabilities - BugSWAT
*
Ezequiel Pereira
Clickjacking on Google MyAccount Worth 7,500$
*
Apapedulimu
GoogleMeetRoulette: Joining random meetings
*
Martin Vigo
Reflected XSS in Google Code Jam
*
Thomas Orlita
Liking GitHub repositories on behalf of other users — Stored XSS in WebComponents.org
*
Thomas Orlita
Waze remote vulnerabilities
*
PanguTeam
Missing access control in Google play store
*
Vishwaraj Bhattrai
$5k Service dependencies
*
Ezequiel Pereira
Stored XSS on biz.waze.com
*
Rojan Rijal
Stored XSS, and SSRF in Google using the Dataset Publishing Language
*
Craig Arendt
Bypassing Google’s authentication to access their Internal Admin panels
*
Vishnu Prasad P G
Google bugs stories and the shiny pixelbook
*
Missoum Said
$7.5k Google services mix-up
*
Ezequiel Pereira
How I hacked Google’s bug tracking system itself for $15,600 in bounties
*
Alex Birsan
nullcon Goa 2017 - Great Bugs In Google VRP In 2016
*
Martin Straka and Karshan Sharma
RuhrSec 2017: Secrets of the Google Vulnerability Reward Program
*
Krzysztof Kotowicz
How I found a $5,000 Google Maps XSS (by fiddling with Protobuf)
*
Marin Moulinier
Ok Google, Give Me All Your Internal DNS Information!
*
Julien Ahrens
Exploiting Clickjacking Vulnerability To Steal User Cookies
*
Jasminder Pal Singh
fastboot oem sha1sum
*
Roee Hay
War Stories from Google’s Vulnerability Reward Program
*
Gábor Molnár
How I got 6000$ from #Google (Google Cloudshell RCE)
*
Pranav Venkat
$500 getClass
*
Ezequiel Pereira
Stored, Reflected and DOM XSS in Google for Work Connect (GWC)
*
Ashar Javed
Creative bug which result Stored XSS on m.youtube.com
*
Sasi Levi
XSS in YouTube Gaming
*
Ashar Javed
Youtube Editor XSS Vulnerability
*
Jasminder Pal Singh
The 5000$ Google XSS
*
Patrik Fehrenbach
Youtube XSS Vulnerability (Stored -> Self Executed)
*
Jasminder Pal Singh
I hate you, so I pawn your Google Open Gallery
*
Ahmad Ashraff
Again, from Nay to Yay in Google Vulnerability Reward Program!
*
Ahmad Ashraff
XSRF and Cookie manipulation on google.com
*
Michele Spagnuolo
Stored XSS in GMail
*
Michele Spagnuolo
Google VRP : oAuth token stealing
*
Harsh Jaiswal
Unauth meetings access
*
Rojan Rijal
XSS vulnerability in Google Cloud Shell’s code editor through mini-browser endpoint
*
Psi
Information leakage vulnerability in Google Cloud Shell’s proxy service
*
Psi
XSS vulnerability in Google Cloud Shell’s code editor through SVG files
*
Psi
CSWSH vulnerability in Google Cloud Shell’s code editor
*
Psi
Open redirects that matter
*
Tomasz Bojarski
Voice Squatting & Voice Masquerading Attack against Amazon Alexa and Google Home Actions
*
???
Blind XSS against a Googler
*
Rojan Rijal
Multiple XSSs on hire.withgoogle.com
*
Rojan Rijal
Auth Issues on hire.withgoogle.com
*
Rojan Rijal
G Suite - Device Management XSS
*
Rojan Rijal