Google erhöht Chrome-Bug-Bounty-Belohnungen auf bis zu $250.000

Teilen:

Google has more than doubled payouts for Google Chrome security flaws reported through its Vulnerability Reward Program, with the maximum possible reward for a single bug now exceeding $250,000.

Starting today, the search giant will differentiate memory corruption vulnerabilities depending on the quality of the report and the researcher’s drive to find the full impact of the reported issues.

The rewards will significantly increase from baseline reports demonstrating Chrome memory corruption with stack traces and a proof-of-concept (with rewards of up to $25,000) to a high-quality report with remote code execution demonstration through a functional exploit.

“It is time to evolve Chrome VRP rewards and amounts to provide an improved structure and clearer expectations for security researchers reporting bugs to us and to incentivize high-quality reporting and deeper research of Chrome vulnerabilities, exploring them to their full impact and exploitability potential,” said Chrome Security engineer Amy Ressler.

“The highest potential reward amount for a single issue is now $250,000 for demonstrated RCE in a non-sandboxed process. If the RCE in a non-sandboxed process can be achieved without a renderer compromise, it is eligible for an even higher amount, to include the renderer RCE reward.”

The company has also more than doubled reward amounts for MiraclePtr bypasses to $250,128 from $100,115 when the MiraclePtr Bypass Reward was launched.

Google also categorizes and will reward reports for other classes of vulnerabilities depending on their quality, impact, and potential harm to Chrome users as:

  • Lower impact: low potential for exploitability, significant preconditions to exploit, low attacker control, low risk/potential for user harm
  • Moderate impact: moderate preconditions to exploit, fair degree of attacker control
  • High impact: straight-forward path to exploitability, demonstrable and significant user harm, remote exploitability, low preconditions to exploit

“All reports are still eligible for bonus rewards when they include the applicable characteristics. We will continue exploring more experimental reward opportunities, similar to the previous Full Chain Exploit Reward, and evolving our program in ways to better serve the security community,” Ressler added.

“Reports that don’t demonstrate security impact or the potential for user harm, or are purely reports of theoretical or speculative issues are unlikely to be eligible for a VRP reward.”

Earlier this month, Google also announced that its Play Security Reward Program (GPSRP) will close for submissions of new reports at the end of this month, on August 31, because of a “decrease in the number of actionable vulnerabilities reported.”

In July, it also launched kvmCTF, a new VRP first unveiled in October 2023 to improve the security of the Kernel-based Virtual Machine (KVM) hypervisor, offering $250,000 bounties for full VM escape exploits.

Since it launched its Vulnerability Reward Program (VRP) in 2010, Google has paid over $50 million in bug bounty rewards to security researchers who reported more than 15,000 vulnerabilities.

Sergiu Gatlan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
7:03 am, Jan. 23, 2025
Wetter-Symbol 3°C
L: 1° | H: 4°
overcast clouds
Luftfeuchtigkeit: 91 %
Druck: 1005 mb
Wind: 5 mph SSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:51 am
Sonnenuntergang: 4:33 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
1° | 4°°C 1 mm 100% 19 mph 89 % 1004 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
6° | 11°°C 1 mm 100% 25 mph 91 % 1003 mb 0 mm/h
Sa. Jan. 25 9:00 pm
Wetter-Symbol
3° | 6°°C 0.36 mm 36% 11 mph 87 % 1008 mb 0 mm/h
So. Jan. 26 9:00 pm
Wetter-Symbol
2° | 7°°C 1 mm 100% 16 mph 96 % 1009 mb 0 mm/h
Mo. Jan. 27 9:00 pm
Wetter-Symbol
7° | 9°°C 1 mm 100% 25 mph 89 % 991 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
3° | 4°°C 0 mm 0% 8 mph 89 % 1004 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
6° | 8°°C 0.79 mm 79% 17 mph 84 % 1002 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
7° | 7°°C 1 mm 100% 19 mph 72 % 998 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
6° | 6°°C 0.8 mm 80% 16 mph 72 % 1003 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 9 mph 80 % 1004 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
6° | 6°°C 0 mm 0% 11 mph 75 % 1003 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
9° | 9°°C 0.53 mm 53% 20 mph 91 % 997 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
9° | 9°°C 1 mm 100% 25 mph 87 % 992 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€98,330.19
-2.83%
Ethereum(ETH)
€3,082.16
-3.01%
XRP(XRP)
€3.01
-1.34%
Fesseln(USDT)
€0.96
-0.04%
Solana(SOL)
€238.31
-3.02%
Dogecoin(DOGE)
€0.339024
-3.75%
USDC(USDC)
€0.96
0.00%
Shiba Inu(SHIB)
€0.000019
-2.82%
Pepe(PEPE)
€0.000014
-6.41%
Peanut das Eichhörnchen(PNUT)
€0.338613
-5.46%
Nach oben scrollen