Google Extends Bug Bounty To Third Party Apps
Written by Kay Ewbank   
Tuesday, 03 September 2019

Google is extending its bug bounty scheme to third party apps in the Google Play Store. The reward will apply to problems found in any app that has more than 100 million installs.

The increase is being made as part of the Google Play Security Reward Program (GPSRP), and Google is also launching a new Developer Data Protection Reward Program (DDPRP).

androidlogo

So long as an app has enough installs, if a bug is found in it the finder will be eligible for a reward, even if the app developers don’t have their own vulnerability disclosure or bug bounty program. If that's the case, Google helps responsibly disclose identified vulnerabilities to the affected app developer. If the developers already have their own programs, researchers can collect rewards directly from them on top of the rewards from Google.

Google says it uses vulnerability data from GPSRP to create automated checks that scan all apps available in Google Play for similar vulnerabilities. Over the lifetime of the App Security Improvement (ASI) program, it has helped more than 300,000 developers fix more than 1,000,000 apps on Google Play.

The news of the extension to the scheme follows an announcement by Google in July that the maximum baseline reward amount was being raised from $5,000 to $15,000 for Chrome bugs, and the amount for high-quality reports from $15,000 to $30,000.

Google has also launched a Developer Data Protection Reward Program. DDPRP is a bounty program that's aimed at identifying and mitigating data abuse issues in Android apps, OAuth projects, and Chrome extensions. The program aims to identify situations where user data is being used or sold unexpectedly, or repurposed in an illegitimate way without user consent. If data abuse is identified related to an app or Chrome extension, that app or extension will be removed from Google Play or Google Chrome Web Store, and if an app developer is abusing access to Gmail restricted scopes, their API access will be removed. Google hasn't so far published a reward table or maximum reward, but the announcement said that depending on impact, a single report could qualify for a reward as large as $50,000.

androidlogo 

More Information

Google Play Security Reward Program

Developer Data Protection Reward Program

Related Articles

EU Bug Bounty - Software Security as a Civil Right

GitHub Bounty Program Increases Rewards

Google Increases Android Bug Rewards

New Android Bug Bounty Scheme

Google Increases Maximum Bounty For Chrome Bugs

 

To be informed about new articles on I Programmer, sign up for our weekly newsletter, subscribe to the RSS feed and follow us on Twitter, Facebook or Linkedin.

Banner


Be Counted In the Python Developer Survey
09/10/2024

Conducted annually by the Python Software Foundation in conjunction with JetBrains, this survey is the major source of knowledge about the current state of the Python community. The eighth iterat [ ... ]



TypeScript Improves Never-Initialized Variables Checks
21/10/2024

Microsoft has announced TypeScript 5.7 in beta, with improvements including stronger checks for variables that have never been initialized before use, and path rewriting for relative paths.


More News

espbook

 

Comments




or email your comment to: comments@i-programmer.info

Last Updated ( Friday, 18 August 2023 )