Google now pays up to $450,000 for RCE bugs in some Android apps

Google

Google has increased rewards for reporting remote code execution vulnerabilities within select Android apps by ten times, from $30,000 to $300,000, with the maximum reward reaching $450,000 for exceptional quality reports.

The company made these changes to the Mobile Vulnerability Rewards Program (Mobile VRP) and they apply to what it describes as Tier 1 applications.

The list of in-scope apps includes Google Play Services, the Android Google Search app (AGSA), Google Cloud, and Gmail.

Google now also wants security researchers to focus on flaws that could lead to sensitive data theft and will now pay them $75,000 for exploits that don’t require user interaction and can be used remotely.

For exceptional quality reports that include a proposed patch or effective mitigation and a root cause analysis to help find other issue variants, the company will pay 1.5x the total reward amount, allowing researchers to earn up to $450,000 for an RCE exploit in a Tier 1 Android app.

However, they’ll get half the reward for low-quality bug reports that don’t provide:

  • Accurate and detailed descriptions,
  • A proof-of-concept exploit,
  • Easy steps to reproduce the vulnerability reliably,
  • A clear demonstration of the bug’s impact.
CategoryRemote/No User InteractionVia link clickVia malicious app /with non-default configAttacker on same network
Code Execution$300,000$150,000$15,000$9,000
Data Theft$75,000$37,500$9,000$6,000
Other Vulns$24,000$9,000$4,500$2,400

“Some additional, smaller changes were also made to our rules. For example, the 2x modifier for SDKs is now baked into the regular rewards. This should increase overall rewards, and will make panel decisions easier,” Google information security engineer Kristoffer Blasiak said.

Google introduced the Mobile VRP last May to pay security researchers for vulnerabilities in the company’s Android applications.

The bug bounty program’s main goal was to speed up the process of discovering and fixing security weaknesses in first-party Android apps maintained or developed by Google.

“The Mobile VRP launched in May 2023, and after one year, it’s time to take a look back at what we’ve achieved,” Blasiak added.

“Most importantly, we received over 40 valid security bug reports, nearing $100,000 in rewards paid to security researchers.”

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Shiba Inu'nun piyasa değerine 3,5 milyar girdi, işler değişti! thumbnail

Shiba Inu’nun piyasa değerine 3,5 milyar girdi, işler değişti!

Shiba Inu ( SHIB ) meme kripto para birimi önemli bir oynaklık yaşarken, token düşüş eğilimini tersine çeviriyor ve ivme kazanıyor gibi görünüyor. Bu içeriği hazırladığımız sıralarda ise meme tokeni, son 24 saatte %22,97 gibi muazzam bir artış ve önceki yedi gün boyunca toplamda %48,29 artışla $0,0000347 dolardan işlem görüyor. Shiba Inu'nun piyasa değerine 3,5 milyar girdi,…
Read More
Arive in the test: What can the new delivery service do for high earners? thumbnail

Arive in the test: What can the new delivery service do for high earners?

Teure Technik und Kosmetik in wenigen Minuten nach Hause geliefert, das verspricht das junge Liefer-Startup Arive. Klappt das? Wir haben es ausprobiert. Das Gorillas für Technikfans und Gutverdiener: Das Liefer-Startup Arive setzt auf ein hochpreisiges Sortiment.Smartmockups/Gründerszene Es ist einer der ganz großen Konsumtrends, den die Corona-Pandemie hervorgebracht hat: Lebensmittel per App bestellen und in wenigen…
Read More
Bug: Defi-Protokoll Compound accidentally sends users 90 million dollars thumbnail

Bug: Defi-Protokoll Compound accidentally sends users 90 million dollars

Defi: Geldsegen für Compound-Community. (Foto: BestForBest/Shutterstock) Compound Labs, die Firma hinter dem Defi-Protokoll Compound, bittet Nutzer:innen, fehlerhaft erhaltenes Geld zurückzugeben. Bis zu 90 Millionen US-Dollar könnten futsch sein. Robert Leshner, Gründer der Krypto-Firma Compound Labs, die das populäre Defi-Staking-Protokoll Compound verantwortet, dürfte ziemlich verzweifelt sein. Mit Zuckerbrot und Peitsche versuchte Leshner am Donnerstag, Compound-Nutzer:innen zu…
Read More
ByteDance Completes Acquisition of Oladance thumbnail

ByteDance Completes Acquisition of Oladance

ByteDance has recently completed the acquisition of Oladance, with existing shareholders including BA Capital and Lanchivc having exited. Back in May of this year, reports emerged that ByteDance had completed its acquisition of Oladance, with the acquisition price ranging between 300 million to 500 million yuan, and a team had been dispatched to the company.
Read More
Tecno shows off its first foldable phone in MWC 2023 thumbnail

Tecno shows off its first foldable phone in MWC 2023

While we have already seen major smartphone announcements on MWC 2023, Tecno is also present in the show and has unveiled the Phantom V Fold, which is the brand’s very first foldable phone that rivals the Galaxy Z Fold4 and Honor Magic Vs. Tecno has opted for a Mediatek Dimensity 9000+ chip to power the
Read More
What a long, strange year it’s been in enterprise tech news thumbnail

What a long, strange year it’s been in enterprise tech news

From Salesforce drama to the year of generative AI Apologies to the Grateful Dead, but what a long, strange year it’s been in 2023 enterprise tech news. It began with a ton of Salesforce drama and eventually got taken over by generative AI and ChatGPT, which seemed to come out of nowhere to completely dominate
Read More
Index Of News
Total
0
Share