Home System Utility Google Triples Chrome Bug Bounties

Google Triples Chrome Bug Bounties

0
Google Triples Chrome Bug Bounties

[ad_1]

Going bug hunting? If so, you might want to turn your attention and expertise to Google’s Chrome browser. The company has now tripled the maximum reward that you could earn for successfully finding an exploit and notifying Google about the issue.

And that maximum is a suggestion, not a hard cap. If you find an especially compelling bug, and you could earn even more.

Meanwhile, if you submitted and were rewarded for bug reports at any point since July 1, 2013, Google will retroactively pay you the higher reward.

Google’s bug bounty will now start at $500 per bug, with payments potentially going up to $15,000 depending on a bug’s severity—triple the previous “maximum” of $5,000. Bug finders will be most likely to earn bounties on the higher end if they can show that the bugs they’ve found “demonstrate a specific attack path against our users,” Tim Willis with the Chrome security team wrote in a blog post(Opens in a new window).

While those researching Chrome bugs can possibly make more by sending the vulnerabilities to a professional broker or, worse, the black market, Google’s increased incentives might convince you to contact the company directly.

“We work hard to keep you safe online. In Chrome, for instance, we warn users against malware and phishing and offer rewards for finding security bugs,” Willis said. “Due in part to our collaboration with the research community, we’ve squashed more than 700 Chrome security bugs and have rewarded more than $1.25 million through our bug reward program. But as Chrome has become more secure, it’s gotten even harder to find and exploit security bugs.”

The reward increase, therefore, is in recognition of the “extra effort it takes to uncover vulnerabilities in Chrome,” he said.

“Researchers now have an option to submit the vulnerability first and follow up with an exploit later. We believe that this a win-win situation for security and researchers: we get to patch bugs earlier and our contributors get to lay claim to the bugs sooner, lowering the chances of submitting a duplicate report,” he added.

And, of course, anyone who successfully finds a bug and is rewarded for it will get an honorary mention in the Google Hall of Fame(Opens in a new window)—permanent, digital glory.

For more, check out Which Browser is Best? Chrome vs. Firefox vs. Internet Explorer.

[ad_2]

Source link : https://www.pcmag.com/news/google-triples-chrome-bug-bounties