Security News > 2020 > August > Mozilla Offering Rewards for Bypassing Firefox Exploit Mitigations

Mozilla Offering Rewards for Bypassing Firefox Exploit Mitigations
2020-08-21 12:58

Mozilla announced on Thursday that it has expanded its bug bounty program with a new category that focuses on bypass methods for the exploit mitigations, security features and defense-in-depth measures in Firefox.

Mozilla says mitigation bypasses have until now been classified as low- or moderate-severity issues, but they are now eligible for a reward associated with a high-severity flaw as part of the new Exploit Mitigation Bug Bounty.

Mozilla says it still encourages researchers to test Firefox Nightly, the testing and development version of the browser, but vulnerabilities found in Nightly will only be eligible for a bounty if they're not found internally by Mozilla within four days of the code change that introduces the flaw being posted to the primary repository.

Some have criticized Mozilla for expanding its bug bounty program shortly after it laid off some of its cybersecurity staff.

The company told SecurityWeek that the recent layoffs did not impact the teams responsible for the security of the Firefox browser and Firefox services.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/IWgEW0D8eO4/mozilla-offering-rewards-bypassing-firefox-exploit-mitigations

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Mozilla 29 13 629 582 266 1490