HomeinetGoogle increases cash rewards for Android security bugs

Google increases cash rewards for Android security bugs

For the one-year anniversary of the Android Security Rewards Program, Google announced that it will be increasing cash rewards since no one was able to crack Android's TrustZone or Verified Boot with a remote exploit.

Google says it has received and approved over 250 valid vulnerability bounties in the past, but unfortunately, over a quarter of those were in third-party code, such as kernel and device driver bugs

The company said it paid out over $550,000 to 82 security researchers, which means the average payout for bugs is $2,200 per bug or $6,700 per researcher.

Google increases cash rewards for Android security bugs

Some researchers were busier than others, and Google said the most prolific bug hunter was @heisecode, who received $75,750 from 26 different vulnerability.

Google did not disclose who received the largest bug bounty, but said 15 researchers earned more than $10,000 from multiple reports.

Because no one was able to perform remote code execution in the Android kernel leading to TrustZone or Verified Boot exposure, the most important and well-protected zone of the operating system, Google decided to entice researchers to try once again to find a solution to this problem.

The company said it would pay $50,000 for a remote chain of exploits or exploits that lead to a TrustZone or Verified Boot compromise. Previously, Google was willing to pay $30,000.

Additionally, the company is increasing the reward for remote or proximal kernel exploits from $20,000 to $30,000.

The reward for an exploit or chain of exploits leading to TrustZone or Verified Boot exposure via an installed application or through physical access to the device remained at $30,000.

On top of that, Google has made it clear that quality vulnerability reports are welcome, increasing all rewards by 33 percent if they include a proof of concept. Researchers will also benefit from a 50 percent increase in their rewards if, in addition to a proof of concept, their reports also include a suite of compatibility tests for older versions of Android.

Finally, last March, Google increased the maximum reward for persistent compromise of a Chromebook device running in guest mode, stating that researchers who achieve such a feat will receive a reward of $100,000.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS