Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Mobile & Wireless

Google Increases Android Bug Bounty Payouts

After paying out more than half a million dollars, Google has decided to increase the rewards offered to researchers who report vulnerabilities through the company’s Android bug bounty program.

After paying out more than half a million dollars, Google has decided to increase the rewards offered to researchers who report vulnerabilities through the company’s Android bug bounty program.

The Android Security Rewards program was launched exactly one year ago, with up to $38,000 offered per submission. Over the past year, 82 researchers reported more than 250 flaws for which they received a total of over $550,000 from Google.

The top researcher, Peter Pi (@heisecode) of Trend Micro, received over $75,000 for 26 vulnerability reports. While more than a dozen experts received $10,000 or more, no one managed to earn the top reward, which Google is offering for a complete remote exploit chain that leads to a compromise of TrustZone or Verified Boot.

Google announced on Thursday that it’s making some improvements to its Android Security Rewards program. The search giant says it has increased rewards by 33 percent for high quality vulnerability reports starting with June 1. For instance, researchers can now earn $4,000 instead of $3,000 for a critical vulnerability report that is accompanied by a proof-of-concept (PoC).

The payout has increased by 50 percent for high quality vulnerability reports that include not only a PoC, but also a CTS test or a patch. Rewards for remote or proximal kernel exploits have been increased from $20,000 to $30,000.

The top reward, the one offered for a remote exploit chain that leads to a TrustZone or Verified Boot compromise, has increased from $30,000 to $50,000.

“While the program is focused on Nexus devices and has a primary goal of improving Android security, more than a quarter of the issues were reported in code that is developed and used outside of the Android Open Source Project. Fixing these kernel and device driver bugs helps improve security of the broader mobile industry (and even some non-mobile platforms),” explained Quan To, security program manager at Google.

Since many of the reported Android vulnerabilities affected Mediaserver’s libstagefright library, Google says it has hardened the component in Android N, the next major version of the mobile operating system.

Advertisement. Scroll to continue reading.

Related Reading: Google Pays $25,000 Reward for Critical Chrome Flaw

Related Reading: Google Offers $100,000 for Chromebook Hack

Related Reading: Google Patches Serious Account Recovery Vulnerabilities

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Discover strategies for vendor selection, integration to minimize redundancies, and maximizing ROI from your cybersecurity investments. Gain actionable insights to ensure your stack is ready for tomorrow’s challenges.

Register

Dive into critical topics such as incident response, threat intelligence, and attack surface management. Learn how to align cyber resilience plans with business objectives to reduce potential impacts and secure your organization in an ever-evolving threat landscape.

Register

People on the Move

Karl Triebes has joined Ivanti as Chief Product Officer.

Steven Hernandez has joined USAID as CISO and Deputy CIO.

Data security and privacy firm Protegrity has named Michael Howard as its CEO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.