Security News > 2023 > June > Google triples reward for Chrome full chain exploits

Google triples reward for Chrome full chain exploits
2023-06-02 12:27

Google has tripled the full reward amount for the first security bug report that includes a functional full chain exploit of its popular Chrome browser.

Six months of higher rewards for a Chrome full chain exploit.

"We're always interested in explorations of new and novel approaches to fully exploit Chrome browser and we want to provide opportunities to better incentivize this type of research," said Amy Ressler from the Chrome Security Team.

"These exploits provide us valuable insight into the potential attack vectors for exploiting Chrome, and allow us to identify strategies for better hardening specific Chrome features and ideas for future broad-scale mitigation strategies."

"The full chain exploit must result in a Chrome browser sandbox escape, with a demonstration of attacker control / code execution outside of the sandbox," said Ressler.

Exploits developed from publicly disclosed security vulnerabilities and/or found in outdated versions of Chrome are not eligible.


News URL

https://www.helpnetsecurity.com/2023/06/02/chrome-full-chain-exploit/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Google 141 995 4854 2783 1620 10252