Google has announced that it’s upping the rewards handed out for its Chromium Bounty Program. The bounty program has apparently begun to stagnate – Google attributes this to vulnerabilities being more difficult to find due to their security efforts – and they hope to increase the input of reported vulnerabilities by increasing the payout.

The Chromium Vulnerability Rewards Program was created to help reward the contributions of security researchers who invest their time and effort in helping us make Chromium more secure. We’ve been very pleased with the response: Google’s various vulnerability reward programs have kept our users protected and netted more than $1 million dollars of total rewards for security researchers. Recently, we’ve seen a significant drop-off in externally reported Chromium security issues. This signals to us that bugs are becoming harder to find, as the efforts of the wider community have made Chromium significantly stronger.

Good news for Chrome users – finding bugs doesn’t just mean that you no longer have to worry about that particular one, it also leads to improvements in how other vulnerabilities are found and how the browser can mitigate entire classes of vulnerabilities in the future.



blog comments powered by Disqus

Published

14 August 2012

Category

security

Tags