Google is attracting more security researchers to participate in the security improvements of the Chrome browser by continuing to increase vulnerability bounties. Google recently announced that it will increase the maximum bounty for a single vulnerability in the Chrome Vulnerability Security Bounty Program to $250,000.

Google security engineers said in a blog:

By adjusting the ChromeVRP reward and amount to provide a better structure and clearer expectations for security researchers involved in Chrome vulnerability research, we will incentivize security researchers to study Chrome security vulnerabilities more deeply and submit higher-quality vulnerability reports.

The maximum potential reward amount for a single vulnerability is now increased to $250,000. This reward level applies to demonstrating RCE (Remote Code Execution) in a non-sandbox process: if RCE of the non-sandbox process can be achieved without breaking the renderer, you are eligible for a higher amount, including the renderer RCE reward.

Google also mentioned that the vulnerability reward amount for MiraclePtr bypass has doubled from $100,115 to $250,128. MiraclePtr is a security mitigation solution launched by Google for Chrome to mitigate the harm of UaF vulnerabilities.

The following is the vulnerability level classified by Google:

  • Vulnerabilities with low impact: very low availability, obvious exploitable conditions, low attacker ability to control, and low risk to users

  • Vulnerabilities with medium impact: The prerequisites for exploitation are moderate, and the attacker's ability to control is moderate.

  • High-impact vulnerabilities: direct exploitable, demonstrably capable of causing significant harm, remotely exploitable, and very low prerequisites

  • All security vulnerability reports are eligible for vulnerability rewards as long as they contain characteristics of the applicable level. At the same time, Google is also exploring more experimental reward opportunities, similar to the previous excessive rewards that could be obtained if full-chain vulnerabilities were discovered.

    Of course, if the submitted report does not demonstrate potential security hazards or causes very little harm to users, or is a purely theoretical or speculative report, it is usually unlikely to receive a reward from Google in this case.