Google Triples Bug Bounty Reward
In recognition of the extra effort it takes to uncover vulnerabilities in Chrome, Gogole is increasing its reward levels and is also making some changes to be more transparent with researchers reporting a bug. Google has increased its usual reward pricing range to $500-$15,000 per bug, up from a previous published maximum of $5,000. This is accompanied with a clear breakdown of likely reward amounts by bug type. As always, Google reserves the right to reward above these levels for particularly great reports.
Google will also pay at the higher end of the range when researchers can provide an exploit to demonstrate a specific attack path against Google's users. Researchers now have an option to submit the vulnerability first and follow up with an exploit later.
In addition, Chrome reward recipients will be listed in the Google Hall of Fame.
As a special treat, Gogole is going to back-pay valid submissions from July 1, 2014 at the new increased reward levels.
Due in part to our collaboration with the research community, Gogole says it has squashed more than 700 Chrome security bugs and has rewarded more than $1.25 million through its bug reward program.