Google Extends Bug Bounty To Third Party Apps
Written by Kay Ewbank   
Tuesday, 03 September 2019

Google is extending its bug bounty scheme to third party apps in the Google Play Store. The reward will apply to problems found in any app that has more than 100 million installs.

The increase is being made as part of the Google Play Security Reward Program (GPSRP), and Google is also launching a new Developer Data Protection Reward Program (DDPRP).

androidlogo

So long as an app has enough installs, if a bug is found in it the finder will be eligible for a reward, even if the app developers don’t have their own vulnerability disclosure or bug bounty program. If that's the case, Google helps responsibly disclose identified vulnerabilities to the affected app developer. If the developers already have their own programs, researchers can collect rewards directly from them on top of the rewards from Google.

Google says it uses vulnerability data from GPSRP to create automated checks that scan all apps available in Google Play for similar vulnerabilities. Over the lifetime of the App Security Improvement (ASI) program, it has helped more than 300,000 developers fix more than 1,000,000 apps on Google Play.

The news of the extension to the scheme follows an announcement by Google in July that the maximum baseline reward amount was being raised from $5,000 to $15,000 for Chrome bugs, and the amount for high-quality reports from $15,000 to $30,000.

Google has also launched a Developer Data Protection Reward Program. DDPRP is a bounty program that's aimed at identifying and mitigating data abuse issues in Android apps, OAuth projects, and Chrome extensions. The program aims to identify situations where user data is being used or sold unexpectedly, or repurposed in an illegitimate way without user consent. If data abuse is identified related to an app or Chrome extension, that app or extension will be removed from Google Play or Google Chrome Web Store, and if an app developer is abusing access to Gmail restricted scopes, their API access will be removed. Google hasn't so far published a reward table or maximum reward, but the announcement said that depending on impact, a single report could qualify for a reward as large as $50,000.

androidlogo 

More Information

Google Play Security Reward Program

Developer Data Protection Reward Program

Related Articles

EU Bug Bounty - Software Security as a Civil Right

GitHub Bounty Program Increases Rewards

Google Increases Android Bug Rewards

New Android Bug Bounty Scheme

Google Increases Maximum Bounty For Chrome Bugs

 

To be informed about new articles on I Programmer, sign up for our weekly newsletter, subscribe to the RSS feed and follow us on, Twitter, Facebook or Linkedin.

Banner


Google Helps With Linux Scheduling With SchedViz
10/10/2019

Google has just open sourced a tool that lets you visualize how your program is being treated under Linux scheduling. The idea is that you can use SchedViz to tune the system.



Unix Celebrates 50 Years
22/10/2019

Today and tomorrow Nokia Bell Labs is hosting a two-day event  celebrating 50 years of the Unix operating system, reflecting on Unix’s past and exploring the future of computing. Speakers  [ ... ]


More News

graphics

 



 

Comments




or email your comment to: comments@i-programmer.info