Google now pays up to $450,000 for RCE bugs in some Android apps

Google

Google has increased rewards for reporting remote code execution vulnerabilities within select Android apps by ten times, from $30,000 to $300,000, with the maximum reward reaching $450,000 for exceptional quality reports.

The company made these changes to the Mobile Vulnerability Rewards Program (Mobile VRP) and they apply to what it describes as Tier 1 applications.

The list of in-scope apps includes Google Play Services, the Android Google Search app (AGSA), Google Cloud, and Gmail.

Google now also wants security researchers to focus on flaws that could lead to sensitive data theft and will now pay them $75,000 for exploits that don’t require user interaction and can be used remotely.

For exceptional quality reports that include a proposed patch or effective mitigation and a root cause analysis to help find other issue variants, the company will pay 1.5x the total reward amount, allowing researchers to earn up to $450,000 for an RCE exploit in a Tier 1 Android app.

However, they’ll get half the reward for low-quality bug reports that don’t provide:

  • Accurate and detailed descriptions,
  • A proof-of-concept exploit,
  • Easy steps to reproduce the vulnerability reliably,
  • A clear demonstration of the bug’s impact.
CategoryRemote/No User InteractionVia link clickVia malicious app /with non-default configAttacker on same network
Code Execution$300,000$150,000$15,000$9,000
Data Theft$75,000$37,500$9,000$6,000
Other Vulns$24,000$9,000$4,500$2,400

“Some additional, smaller changes were also made to our rules. For example, the 2x modifier for SDKs is now baked into the regular rewards. This should increase overall rewards, and will make panel decisions easier,” Google information security engineer Kristoffer Blasiak said.

Google introduced the Mobile VRP last May to pay security researchers for vulnerabilities in the company’s Android applications.

The bug bounty program’s main goal was to speed up the process of discovering and fixing security weaknesses in first-party Android apps maintained or developed by Google.

“The Mobile VRP launched in May 2023, and after one year, it’s time to take a look back at what we’ve achieved,” Blasiak added.

“Most importantly, we received over 40 valid security bug reports, nearing $100,000 in rewards paid to security researchers.”

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Show HN: Ellipsis – Automated PR reviews and bug fixes thumbnail

Show HN: Ellipsis – Automated PR reviews and bug fixes

Trusted by 1,400+ Github USERSEllipsis is an AI developer tool that automatically reviews code and fixes bugs on pull requests.Ellipsis is an AI teammate capable of answering questions, creating release notes, feature development, and fixing build issues.Ellipsis doesn't persist your source code anywhere. Period. It only lives on our servers in a private AWS VPC
Read More

Installation of the “Honghuang 70” High-temperature Superconducting Tokamak Commences

On August 15th, according to the official WeChat account of Energy Singularity, the overall installation of the “Honghuang 70” high-temperature superconducting tokamak device has officially commenced. The “Honghuang 70” is designed, developed, and constructed by Energy Singularity, with the overall installation being undertaken by China Nuclear Industry Fifth Construction Co., Ltd. According to the introduction
Read More
Omnivision was driving people crazy with the 0.61 microns pixel 200MP OVB0B thumbnail

Omnivision was driving people crazy with the 0.61 microns pixel 200MP OVB0B

Η Samsung έκανε το άλμα σε έναν αισθητήρα εικόνας 200MP σε αισθητήρα εικόνας CMOS που μπορεί να εμφανιστεί στα smartphone της επόμενης γενιάς. Τώρα, η OmniVision αμφισβήτησε τη δυνητική κυριαρχία του ISOCELL HP1 με το OVB0B, στην CES 2022. Με μεμονωμένα pixel 0.61 microns (μm) σε 1/1.28 ίντσες, μπορεί να είναι το μικρότερο στοιχείο με…
Read More
Έτσι βλέπεις την ποιότητα του σήματος σε διάφορα σημεία του σπιτιού! thumbnail

Έτσι βλέπεις την ποιότητα του σήματος σε διάφορα σημεία του σπιτιού!

Please enable cookies. You are unable to access techmaniacs.gr Why have I been blocked? This website is using a security service to protect itself from online attacks. The action you just performed triggered the security solution. There are several actions that could trigger this block including submitting a certain word or phrase, a SQL command…
Read More
To Oscar-nominasjoner til «Verdens verste menneske» thumbnail

To Oscar-nominasjoner til «Verdens verste menneske»

Kunngjøringen om at filmen var én av de fem nominerte kom tirsdag ettermiddag da alle kandidatene i de til sammen 23 kategoriene ble gjort kjent av Oscar-komiteen. «Verdens verste menneske» var en klar favoritt da den norske Oscar-komiteen skulle avgjøre hvilken norsk film som skulle representere Norge til den 94. Oscar-utdelingen, som finner sted 27.…
Read More
Index Of News
Total
0
Share