Whitehat: "maybe just responsibly disclose after all?"
Google: sure! memory corruption ā $500, controlled write ā $5k.
And it's not enough to just find the bug ā the PoC has to land as the right files, no harness/shell scripts/CDP, with a flawless repro on their end.
The industry itself is handing wavering whitehats a one-way ticket to "enjoy cybercrime."
š£š¢ Calling all Android and Chrome bug hunters š§āš»š!
We're updating our Android & Chrome VRP programs to ensure we can continue to reward the most challenging and impactful vulnerabilities researchers find in our products. For details, š
bughunters.google.com/blog/eā¦