Google has changed its Vulnerability Reward Program to give higher payouts. It also expects more detailed reports from security researchers and they will be ranked as High, Medium, and Low impact.
Vulnerability reward program RSS
Google has revealed an expansion to its Vulnerability Reward Program (VRP). It is designed to encourage privately reporting security flaws in open source software in exchange for monetary rewards.
Google has decided to launch a new dedicated website that unifies the different VRPs and makes publishing bug reports and submissions easier. This is to celebrate 10 years of its VRP.
A student from Uruguay has been rewarded by Google with $10,000 after he found a security issue that could have been used by hackers to steal sensitive information. The flaw has since been fixed.