Jump to content
  • Google now pays up to $450,000 for RCE bugs in some Android apps


    Karlston

    • 79 views
    • 2 minutes
     Share


    • 79 views
    • 2 minutes

    Google has increased rewards for reporting remote code execution vulnerabilities within select Android apps by ten times, from $30,000 to $300,000, with the maximum reward reaching $450,000 for exceptional quality reports.

     

    The company made these changes to the Mobile Vulnerability Rewards Program (Mobile VRP) and they apply to what it describes as Tier 1 applications.

     

    The list of in-scope apps includes Google Play Services, the Android Google Search app (AGSA), Google Cloud, and Gmail.

     

    Google now also wants security researchers to focus on flaws that could lead to sensitive data theft and will now pay them $75,000 for exploits that don't require user interaction and can be used remotely.

     

    For exceptional quality reports that include a proposed patch or effective mitigation and a root cause analysis to help find other issue variants, the company will pay 1.5x the total reward amount, allowing researchers to earn up to $450,000 for an RCE exploit in a Tier 1 Android app.

     

    However, they'll get half the reward for low-quality bug reports that don't provide:

     

    • Accurate and detailed descriptions,
    • A proof-of-concept exploit,
    • Easy steps to reproduce the vulnerability reliably,
    • A clear demonstration of the bug's impact.

     

    Category Remote/No User Interaction Via link click Via malicious app /with non-default config Attacker on same network
    Code Execution $300,000 $150,000 $15,000 $9,000
    Data Theft $75,000 $37,500 $9,000 $6,000
    Other Vulns $24,000 $9,000 $4,500 $2,400

     

    "Some additional, smaller changes were also made to our rules. For example, the 2x modifier for SDKs is now baked into the regular rewards. This should increase overall rewards, and will make panel decisions easier," Google information security engineer Kristoffer Blasiak said.

     

    Google introduced the Mobile VRP last May to pay security researchers for vulnerabilities in the company's Android applications.

     

    The bug bounty program's main goal was to speed up the process of discovering and fixing security weaknesses in first-party Android apps maintained or developed by Google.

     

    "The Mobile VRP launched in May 2023, and after one year, it's time to take a look back at what we've achieved," Blasiak added.

     

    "Most importantly, we received over 40 valid security bug reports, nearing $100,000 in rewards paid to security researchers."

     

    Source


    User Feedback

    Recommended Comments

    There are no comments to display.



    Join the conversation

    You can post now and register later. If you have an account, sign in now to post with your account.
    Note: Your post will require moderator approval before it will be visible.

    Guest
    Add a comment...

    ×   Pasted as rich text.   Paste as plain text instead

      Only 75 emoji are allowed.

    ×   Your link has been automatically embedded.   Display as a link instead

    ×   Your previous content has been restored.   Clear editor

    ×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...