Google now pays up to $450,000 for RCE bugs in some Android apps

Google

Google has increased rewards for reporting remote code execution vulnerabilities within select Android apps by ten times, from $30,000 to $300,000, with the maximum reward reaching $450,000 for exceptional quality reports.

The company made these changes to the Mobile Vulnerability Rewards Program (Mobile VRP) and they apply to what it describes as Tier 1 applications.

The list of in-scope apps includes Google Play Services, the Android Google Search app (AGSA), Google Cloud, and Gmail.

Google now also wants security researchers to focus on flaws that could lead to sensitive data theft and will now pay them $75,000 for exploits that don’t require user interaction and can be used remotely.

For exceptional quality reports that include a proposed patch or effective mitigation and a root cause analysis to help find other issue variants, the company will pay 1.5x the total reward amount, allowing researchers to earn up to $450,000 for an RCE exploit in a Tier 1 Android app.

However, they’ll get half the reward for low-quality bug reports that don’t provide:

  • Accurate and detailed descriptions,
  • A proof-of-concept exploit,
  • Easy steps to reproduce the vulnerability reliably,
  • A clear demonstration of the bug’s impact.
CategoryRemote/No User InteractionVia link clickVia malicious app /with non-default configAttacker on same network
Code Execution$300,000$150,000$15,000$9,000
Data Theft$75,000$37,500$9,000$6,000
Other Vulns$24,000$9,000$4,500$2,400

“Some additional, smaller changes were also made to our rules. For example, the 2x modifier for SDKs is now baked into the regular rewards. This should increase overall rewards, and will make panel decisions easier,” Google information security engineer Kristoffer Blasiak said.

Google introduced the Mobile VRP last May to pay security researchers for vulnerabilities in the company’s Android applications.

The bug bounty program’s main goal was to speed up the process of discovering and fixing security weaknesses in first-party Android apps maintained or developed by Google.

“The Mobile VRP launched in May 2023, and after one year, it’s time to take a look back at what we’ve achieved,” Blasiak added.

“Most importantly, we received over 40 valid security bug reports, nearing $100,000 in rewards paid to security researchers.”

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Unmanned Industrial Vehicle Firm VisionNav Robotics Bags Several Hundred Million Yuan with ByteDance as Investor thumbnail

Unmanned Industrial Vehicle Firm VisionNav Robotics Bags Several Hundred Million Yuan with ByteDance as Investor

(Source: VisionNav Robotics) VisionNav Robotics, a vision guided vehicle provider for warehouse and factory operations, announced on Thursday the completion of a C-round of equity financing worth several hundred million yuan, with investors including ByteDance, Lenovo Capital and Incubator Group, Shunwei Capital, Unicom CICC, IDG Capital and Eastern Bell Capital. The company says that this…
Read More
Huawei Petal Maps to be Launched in China, Equipped on AITO M5 EV thumbnail

Huawei Petal Maps to be Launched in China, Equipped on AITO M5 EV

(Source: Huawei Update) Your browser doesn’t support HTML5 audio Recently, Ma Xiaoqiang, VP of Huawei’s Consumer Business Group for the Asia Pacific region, posted some pictures of the Huawei P50 Pocket which showed an app called Petal Maps. Ma, however, is currently located in Kuala Lumpur, Malaysia. Shortly after Ma took posted the photos, digital…
Read More
Coronavirus: What the Modern Vaccine Contains (VIDEO) thumbnail

Coronavirus: What the Modern Vaccine Contains (VIDEO)

Daca erati curiosi sa aflati ce contine vaccinul Moderna impotriva Coronavirus, ei bine acum aveti ocazia de a afla acest lucru multumita unei explicatii oferite de catre un doctor pentru cei care inca nu erau convinsi daca ar trebui sa fie imunizati, sau nu, in aceasta perioada. “Ce conține vaccinul Moderna pe înțelesul tuturor! Lista…
Read More
Index Of News
Total
0
Share