Google now pays $250,000 for KVM zero-day vulnerabilities

Share:

Google has launched kvmCTF, a new vulnerability reward program (VRP) first announced in October 2023 to improve the security of the Kernel-based Virtual Machine (KVM) hypervisor that comes with $250,000 bounties for full VM escape exploits.

KVM, an open-source hypervisor with over 17 years of development, is a crucial component in consumer and enterprise settings, powering Android and Google Cloud platforms.

An active and key KVM contributor, Google developed kvmCTF as a collaborative platform to help identify and fix vulnerabilities, bolstering this vital security layer.

Like Google’s kernelCTF vulnerability reward program, which targets Linux kernel security flaws, kvmCTF focuses on VM-reachable bugs in the Kernel-based Virtual Machine (KVM) hypervisor.

The goal is to execute successful guest-to-host attacks, and QEMU or host-to-KVM vulnerabilities will not be awarded.

Security researchers who enroll in the program are provided with a controlled lab environment where they can use exploits to capture flags. However, unlike other vulnerability reward programs, kvmCTF focuses on zero-day vulnerabilities and will not reward exploits targeting known vulnerabilities.

The reward tiers for kvmCTF are as follows:

  • Full VM escape: $250,000
  • Arbitrary memory write: $100,000
  • Arbitrary memory read: $50,000
  • Relative memory write: $50,000
  • Denial of service: $20,000
  • Relative memory read: $10,000

The kvmCTF infrastructure is hosted on Google’s Bare Metal Solution (BMS) environment, highlighting the program’s commitment to high-security standards.

“Participants will be able to reserve time slots to access the guest VM and attempt to perform a guest-to-host attack. The goal of the attack must be to exploit a zero day vulnerability in the KVM subsystem of the host kernel,” said Google software engineer Marios Pomonis.

“If successful, the attacker will obtain a flag that proves their accomplishment in exploiting the vulnerability. The severity of the attack will determine the reward amount, which will be based on the reward tier system explained below. All reports will be thoroughly evaluated on a case-by-case basis.”

Google will receive details of discovered zero-day vulnerabilities only after upstream patches are released, ensuring the information is shared with the open-source community simultaneously.

To get started, participants must review the kvmCTF rules, which include information on reserving time slots, connecting to the guest VM, obtaining flags, mapping various KASAN violations to reward tiers, as well as detailed instructions on reporting vulnerabilities.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
5:13 am, Jun 18, 2025
weather icon 15°C
L: 13° | H: 17°
overcast clouds
Humidity: 81 %
Pressure: 1024 mb
Wind: 1 mph W
Wind Gust: 3 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 87%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:42 am
Sunset: 9:20 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
13° | 17°°C 0 mm 0% 8 mph 80 % 1025 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
18° | 28°°C 0 mm 0% 11 mph 75 % 1026 mb 0 mm/h
Fri Jun 20 10:00 pm
weather icon
17° | 28°°C 0 mm 0% 11 mph 68 % 1026 mb 0 mm/h
Sat Jun 21 10:00 pm
weather icon
17° | 32°°C 0 mm 0% 10 mph 65 % 1022 mb 0 mm/h
Sun Jun 22 10:00 pm
weather icon
22° | 33°°C 0 mm 0% 14 mph 45 % 1018 mb 0 mm/h
Today 7:00 am
weather icon
15° | 16°°C 0 mm 0% 4 mph 80 % 1024 mb 0 mm/h
Today 10:00 am
weather icon
20° | 22°°C 0 mm 0% 4 mph 65 % 1025 mb 0 mm/h
Today 1:00 pm
weather icon
26° | 26°°C 0 mm 0% 5 mph 38 % 1025 mb 0 mm/h
Today 4:00 pm
weather icon
28° | 28°°C 0 mm 0% 7 mph 35 % 1024 mb 0 mm/h
Today 7:00 pm
weather icon
26° | 26°°C 0 mm 0% 8 mph 41 % 1024 mb 0 mm/h
Today 10:00 pm
weather icon
22° | 22°°C 0 mm 0% 3 mph 55 % 1025 mb 0 mm/h
Tomorrow 1:00 am
weather icon
20° | 20°°C 0 mm 0% 2 mph 68 % 1025 mb 0 mm/h
Tomorrow 4:00 am
weather icon
18° | 18°°C 0 mm 0% 3 mph 75 % 1025 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,705.63
-2.24%
Ethereum(ETH)
€2,205.29
-2.90%
Tether(USDT)
€0.87
-0.01%
XRP(XRP)
€1.89
-3.52%
Solana(SOL)
€129.55
-3.01%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.148995
-2.41%
Shiba Inu(SHIB)
€0.000010
-2.56%
Pepe(PEPE)
€0.000009
-4.83%
Scroll to Top