Google wants to pay you for finding security flaws in its biggest Android apps

Security Bug
(Image credit: Shutterstock)

Google has announced a new Android bug bounty program offering rewards in the tens of thousands for those looking to try out their expertise.

The new Mobile Vulnerability Reward Program (VRP) was announced on Twitter, where the company noted, “We are excited to announce the new Mobile VRP! We are looking for bughunters to help us find and fix vulnerabilities in our mobile applications.”

According to the program summary, first-party Android apps are the key focus of this Mobile VRP, where vulnerabilities are hoped to be found and eliminated to keep users’ data safe.

Android bug bounty program

Tier 1 applications are considered in scope for the program, comprising Google Play Services, AGSA, Google Chrome, Google Cloud, Gmail, and Chrome Remote Desktop.

Beyond the above, Tier 1 apps, the program also considers apps made by the following developers: Google LLC, Developed with Google, Research at Google, Red Hot Labs, Google Samples, Fitbit LLC, Nest Labs Inc., Waymo LLC, Waze.

Rewards start at $500, which applies to the theft of sensitive data or other vulnerabilities in Tier 3 applications, whereby the attacker was found to be on the same network. Remote arbitrary code execution offers the most lucrative reward, whereby prizes are rated at $30,000, $25,000, and $20,000 for Tiers 1, 2, and 3 respectively.

Additionally, the program’s panel has been authorized to award discretionary $1,000 bonuses for various reasons, like “for a particularly surprising vulnerability, or an exceptional writeup.”

As well as arbitrary code execution and the theft of sensitive data, the Mobile VRP states that other vulnerabilities “will be taken into consideration if they are shown to have a security impact.”

Examples of non-qualifying discoveries, along with more detailed information about the program, can be found on the Mobile VRP website.

TOPICS
Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
Application Security Testing Concept with Digital Magnifying Glass Scanning Applications to Detect Vulnerabilities - AST - Process of Making Apps Resistant to Security Threats - 3D Illustration
Google bug bounty payments hit nearly $12 million in 2024
A woman at a table using a Windows laptop, opposite sits a man, neither show their face
Microsoft will now pay you even more to find security bugs in Copilot
Facebook on laptop
Researcher nets major reward for finding Facebook bug able to unlock the gates to its internal systems
An Android phone being held in the hand
These malicious Android apps were installed over 60 million times - here's how to stay safe
An Android phone being held in the hand
Google is ramping up Android security protection with new Android app safety tools
the YouTube logo on a screen in front of other YouTube logos covering a black background
Worrying YouTube security flaw exposed billions of user emails
Latest in Security
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Oracle
Oracle denies data breach after hacker claims to hold six million records
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Latest in News
A phone showing a ChatGPT app error message
ChatGPT was down for many – here's what's happened
AirPods Max with USB-C in every color
Apple's AirPods Max with USB-C will get lossless audio in April, but you'll need to go wired
A woman sitting in a chair looking at a Windows 11 laptop
It looks like Microsoft might have thought better about banishing Copilot AI shortcut from Windows 11
US flags
US government IT contracts set to be centralized in new Trump order
Tesla Roadster 2
Tesla is still taking deposits on its long overdue Roadster, despite promising it would arrive in 2020
Samsung HW-Q990D soundbar with Halloween theme over the top
Samsung promises to repair soundbars bricked by its disastrous software update for free – but it'll probably involve shipping