Google Inc. about increasing the amounts credited within the rewards for identifying vulnerabilities in the Chrome browser and its underlying components.
The maximum payout for creating an exploit to escape the sandbox environment has increased from $15,000 to $30,000, for
the method of bypassing access restrictions in JavaScript (XSS) from $7,500 to $20,000, for organizing remote code execution at the rendering system level from $7,500 to $10,000, and for identifying information leaks—from $4,000 to $5,000-$20,000. Payments have been introduced for spoofing methods in the user interface ($7,500), privilege escalation in the web platform ($5,000), and exploits bypassing vulnerability protections ($5,000). Rewards for preparing a quality and basic description (test for demonstrating the issue and Chrome version) of a vulnerability without demonstrating an exploit have doubled.
Additionally, researchers have been given the option for phased submission of a report—initially reporting the fact of a vulnerability, and later providing an exploit to receive a higher reward. Also, the bonus payout for identifying a vulnerability using Chrome Fuzzer has increased by up to $1,000.
For Chrome OS, the amount for an exploit for full compromise of a Chromebook or Chromebox from guest mode has been increased to $150,000. New payments have been added for vulnerabilities in firmware and the lock screen system.
In the rewards for vulnerabilities in from Google Play, the value of information about remotely exploitable vulnerabilities has increased from $5,000 to $20,000, data leaks, and access to protected components from $1,000 to $3,000.
Source: opennet.ru
