Google has increased the reward for identifying vulnerabilities in Android to $1.5 million, and in Chrome – to $500 thousand.

Google has announced an expansion of its rewards program for discovering vulnerabilities in the Android platform, Chrome browser, and their underlying components. The maximum reward for creating an exploit for the Android platform that allows code execution at the level of the Pixel Titan M2 chip without any user action (zero-click) is set at $1.5 million, provided the attacker can gain a foothold in the system, and $750,000 for attacks that do not establish persistent control over the system. Additionally, rewards have been established for extracting protected confidential data (up to $375,000) and bypassing the lock screen (up to $150,000).

The maximum reward for creating an exploit for Chrome that allows bypassing all levels of browser isolation and executing code in the system upon opening a web page has been increased to $250,000. An additional bonus of $250,000 ($250,128) is available if the exploit involves memory operations protected by the MiraclePtr mechanism. MiraclePtr provides a wrapper over pointers that performs additional checks and aborts execution upon detecting access to freed memory areas.

Moreover, for Chrome, there are rewards of up to $10,000 for bypassing site isolation or access restrictions in JavaScript (XSS), up to $5,000 for bypassing storage restrictions, exploiting rendering processes, extracting user information, and spoofing URLs in the address bar, as well as from $500 to $7,500 for other types of vulnerabilities. For Chrome OS-specific vulnerabilities, rewards of up to $30,000 plus $10,000 for developing a fix are established.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster