HomeSecurityGoogle: Expands exploit reward programs for Chrome V8, Google Cloud

Google: Expands exploit reward programs for Chrome V8, Google Cloud

Google's research team has launched v8CTF , a capture-the-flag (CTF) challenge focused on the Chrome browser's V8 JavaScript engine , and we could say that it is an extension of the company's exploit reward programs .

Google exploit reward

The contest started on October 6, 2023 and is open to all exploit creators. “Once you find a vulnerability in our release, exploit it and grab the flag,” note Google software engineers Stephen Roettger and Marios Pomonis.

Contestants can either try to find known vulnerabilities (n-days) or discover new ones (zero-days or 0-days). However, the exploits they create must be “relatively stable.” According to the company, this means they can be executed in less than five minutes and have at least an 80% success rate.

See also: Google Mobile VRP: New bug bounty program for Android apps

“If the bug that led to the initial memory corruption was discovered by you, i.e. reported from the same email address used in the v8CTF submission, we will consider the exploit a zero-day submission. All other exploits are considered n-day submissions,” Google explained.

Valid submissions will receive a $10,000 reward. The v8CTF challenge is set to complement Chrome Vulnerability Reward Program (VRP), meaning exploit who discover a zero-day exploit are eligible for an additional reward of up to $180,000.

Google Cloud V8
Google: Expands exploit reward programs for Chrome V8, Google Cloud

Capture-the-Flag: Google will offer up to $99,999

Google also revealed the rules for kvmCTF , another CTF challenge focused on Google Cloud 's kernel-based virtual machine (KVM) (to be released later this year).

See also: OpenAI: Bug Bounty Program with rewards up to $20,000

For this competition, candidates will be asked to execute a successful guest-to-host attack based on 0-day and (patched) 1-day exploits

Google announced the rewards:

  • $99,999 for full VM escape
  • $34,999 for arbitrary (host) memory write exploits
  • $24,999 for arbitrary (host) memory read exploits
  • $14,999 for denial-of-service exploit affecting the host computer

Google encouraged researchers to publish their submissions in order to help the community learn from each other's techniques.

See also: Google Bug Bounty: $12 million awarded to researchers in 2022

Chrome V8 submission process

  1. If your exploit targets a zero-day vulnerability, be sure to report it to the Chrome VRP first.
  2. Check if there is already a submission for the current V8 development version.
  3. Exploit the bug and get the flag from our v8CTF environment.
  4. Create a .tar.gz file of your exploit and calculate its sha256.
  5. Fill out a form with the flag and exploit sha256 sum. For zero-day, submitters are asked to use the same email address from which they reported the bug.
  6. A bug on the Google Issue Tracker will be filed on behalf of the candidates. Attach the exploit that matches the sha256 sum and a short write-up to the bug.
  7. Google will take a few days to validate each submission.

Exploit and bug reward programs

Product bug bounty programs have become an essential part of the broader IT security framework for many technology companies. Essentially, companies challenge developers and security experts to find and disclose vulnerabilities in their products or services, offering them rewards for their efforts. 

These programs are not just an attractive way to utilize the talents of independent researchers. They also provide an effective method for detecting and eliminating bugs that could lead to a breach. Vulnerability reporting can lead to more effective security solutions and allow companies to fix existing bugs before they become public. 

The Prospects of Bug Bounty Programs 

The prospects for bug bounty programs look promising. With the expansion of these programs into areas like Chrome V8 and Google Cloud, it's clear that Google continues to recognize their value and increase its investment in them.

Source: www.infosecurity-magazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS