{
  "total_reports": 4779,
  "total_bounty": 28825171.7,
  "avg_bounty": 6036.69,
  "by_year": {
    "2009": {
      "count": 3,
      "total_bounty": 2000.0
    },
    "2010": {
      "count": 84,
      "total_bounty": 64685.0
    },
    "2011": {
      "count": 190,
      "total_bounty": 193728.0
    },
    "2012": {
      "count": 181,
      "total_bounty": 400007.0
    },
    "2013": {
      "count": 130,
      "total_bounty": 251349.0
    },
    "2014": {
      "count": 180,
      "total_bounty": 570471.0
    },
    "2015": {
      "count": 211,
      "total_bounty": 652777.7
    },
    "2016": {
      "count": 246,
      "total_bounty": 738970.0
    },
    "2017": {
      "count": 214,
      "total_bounty": 604511.0
    },
    "2018": {
      "count": 277,
      "total_bounty": 739948.0
    },
    "2019": {
      "count": 294,
      "total_bounty": 1068707.0
    },
    "2020": {
      "count": 273,
      "total_bounty": 1809200.0
    },
    "2021": {
      "count": 421,
      "total_bounty": 3162500.0
    },
    "2022": {
      "count": 471,
      "total_bounty": 2910500.0
    },
    "2023": {
      "count": 501,
      "total_bounty": 2748837.0
    },
    "2024": {
      "count": 382,
      "total_bounty": 3448981.0
    },
    "2025": {
      "count": 288,
      "total_bounty": 3427500.0
    },
    "2026": {
      "count": 428,
      "total_bounty": 5988000.0
    }
  },
  "by_severity": {
    "S3-Low": 4158,
    "S4-Minimal": 541,
    "Unknown": 70,
    "S1-High": 8,
    "S0-Critical": 1,
    "S2-Medium": 1
  },
  "by_status": {
    "Assigned": 3708,
    "Accepted": 765,
    "New": 149,
    "Fixed": 99,
    "Verified": 57,
    "Unknown": 1
  },
  "by_component": {
    "Blink": 2120,
    "Internals": 1055,
    "UI": 637,
    "Unknown": 353,
    "Platform": 272,
    "Blink, Blink": 80,
    "Mobile": 58,
    "Dawn": 47,
    "Internals, Internals": 41,
    "OS": 16,
    "Enterprise": 12,
    "Blink, Internals, Internals": 12,
    "Blink, Internals": 9,
    "PDFium": 7,
    "Speed": 7,
    "Services (Use Subcomponents)": 6,
    "Infra": 6,
    "Privacy": 5,
    "UI, UI": 5,
    "IO": 4
  },
  "bounty_histogram": [
    {
      "range": "$0-500",
      "count": 6
    },
    {
      "range": "$500-1K",
      "count": 613
    },
    {
      "range": "$1K-3K",
      "count": 1562
    },
    {
      "range": "$3K-5K",
      "count": 749
    },
    {
      "range": "$5K-10K",
      "count": 1047
    },
    {
      "range": "$10K-20K",
      "count": 460
    },
    {
      "range": "$20K+",
      "count": 338
    }
  ],
  "top_bounties": [
    {
      "id": "503197487",
      "title": "ipcz bug can allow renderer duplicate browser process handle to escape sandbox",
      "bounty_amount": 250000.0,
      "severity": "S3-Low",
      "year": 2026
    },
    {
      "id": "493747593",
      "title": "Qualcomm Wild exploited CVE-2025-27038 bypass",
      "bounty_amount": 250000.0,
      "severity": "S4-Minimal",
      "year": 2026
    },
    {
      "id": "481277120",
      "title": "ipcz bug can allow renderer duplicate browser process handle to escape sandbox",
      "bounty_amount": 250000.0,
      "severity": "S3-Low",
      "year": 2026
    },
    {
      "id": "453094710",
      "title": "Out-of-bound read in the jmp table of ActiveMediaSessionController leads to sandbox escape.",
      "bounty_amount": 250000.0,
      "severity": "S3-Low",
      "year": 2025
    },
    {
      "id": "412578726",
      "title": "ipcz bug can allow renderer duplicate browser process handle to escape sandbox",
      "bounty_amount": 250000.0,
      "severity": "S3-Low",
      "year": 2025
    },
    {
      "id": "40079096",
      "title": "Security: Pwnium 4 GeoHot tracking bug",
      "bounty_amount": 150000.0,
      "severity": "S4-Minimal",
      "year": 2014
    },
    {
      "id": "377803496",
      "title": "MiraclePtr bypass due to PtrCount overflow",
      "bounty_amount": 100115.0,
      "severity": "S3-Low",
      "year": 2024
    },
    {
      "id": "340122160",
      "title": "MiraclePtr bypass due to PtrCount overflow",
      "bounty_amount": 100115.0,
      "severity": "S3-Low",
      "year": 2024
    },
    {
      "id": "446722008",
      "title": "heap-use-after-free in content::indexed_db::Database::connections_ when force_closing_ is true",
      "bounty_amount": 100000.0,
      "severity": "S3-Low",
      "year": 2025
    },
    {
      "id": "40089045",
      "title": "Chrome OS exploit: WebAsm, Site Isolation, crosh, crash reporter, cryptohomed",
      "bounty_amount": 100000.0,
      "severity": "S3-Low",
      "year": 2017
    },
    {
      "id": "498904293",
      "title": "Arbitrary Memory Read and Write in ANGLE GL Backend via PBO Desync",
      "bounty_amount": 97000.0,
      "severity": "S3-Low",
      "year": 2026
    },
    {
      "id": "490170083",
      "title": "ANGLE BlitGL copySubTextureCPUReadback Controlled Heap Overflow via Unsynchronized PACK_ROW_LENGTH",
      "bounty_amount": 90000.0,
      "severity": "S3-Low",
      "year": 2026
    },
    {
      "id": "487338366",
      "title": "Use-after-free in CreateNewWindow via SINGLETON_TAB disposition leads to sandbox escape",
      "bounty_amount": 90000.0,
      "severity": "S3-Low",
      "year": 2026
    },
    {
      "id": "485935305",
      "title": "Arbitrary Memory Read/Write via WebGLBuffer Created During Context Loss Combined with PBO Operations",
      "bounty_amount": 90000.0,
      "severity": "S4-Minimal",
      "year": 2026
    },
    {
      "id": "493256564",
      "title": "ANGLE Metal Stale mFormat Cache causes GPU OOB WRITE",
      "bounty_amount": 77000.0,
      "severity": "S3-Low",
      "year": 2026
    },
    {
      "id": "40093479",
      "title": "Security: ChromeOS Persistent root Command Execution",
      "bounty_amount": 75000.0,
      "severity": "S3-Low",
      "year": 2018
    },
    {
      "id": "491518608",
      "title": "Use-After-Free in Dawn Wire Server Uncaptured-Error Callback via Incomplete Device Unregistration Cleanup",
      "bounty_amount": 70000.0,
      "severity": "S3-Low",
      "year": 2026
    },
    {
      "id": "433533359",
      "title": "Consumers of ReadableStream subject to data race with SharedArrayBuffer, leading to RCE + V8 Sandbox bypass",
      "bounty_amount": 70000.0,
      "severity": "S3-Low",
      "year": 2025
    },
    {
      "id": "400086889",
      "title": "Arbitrary Wasm type confusion due to transient canonical index overflow",
      "bounty_amount": 62000.0,
      "severity": "S3-Low",
      "year": 2025
    },
    {
      "id": "40076417",
      "title": "Security: Pwnium 2 TCMalloc profile bug",
      "bounty_amount": 60000.0,
      "severity": "S3-Low",
      "year": 2012
    }
  ]
}