In an announcement on Friday, Facebook said it would increase rewards in bug bounty for discovering vulnerabilities in Hermes and Spark AR.

Hermes is an open-source JavaScript engine , released by Facebook a year ago, and used by the company's React Native apps for Android and other software, including Spark AR, an augmented reality platform used to create effects on Facebook, Instagram , and even the company's smart displays.
Vulnerabilities found in Facebook's native code are covered by the bug bounty program, but as the company stated, it wants to encourage more researchers to work on Hermes and Spark AR, which is why it has added other rewards.
For example, an ethical hacker could earn up to $25,000 if they identify a vulnerability or exploit chain that allows remote code execution when running a Spark AR effect.
"The amount may be adjusted depending on the specific bug and exploit. For example, an exploit chain that does not contain an ASLR bypass may result in a slightly lower reward. Similarly, an out-of-bounds write where there is no clear path to the RCE will receive a lower reward," Facebook explained

A vulnerability that allows an attacker to read user data can be worth, on average, $15,000. DoS resulting from out-of-bounds errors can bring researchers between $500 and $3,000 in profits.
A researcher can also earn a $15,000 reward if they provide the company with a full proof-of-concept (PoC) for an exploit, meaning they could receive $40,000 for a vulnerability .
Last year alone, Facebook awarded more than $2.2 million to its bug bounty program, and a total of nearly $10 million since the program began in 2011.
