Google has increased the security of its first-party Android applications by launching the Mobile Vulnerability Reward Program (Mobile VRP).
tech giant announced on Twitter Monday, hours after we published our new initiative.
Mobile VRP aims to encourage researchers and security professionals to identify and report vulnerabilities in Android apps developed or maintained by Google.
The program is aware of vulnerabilities that fall into two main categories: Arbitrary Code Execution (ACE) and Sensitive Data Theft.
Read more about Google’s commitment to privacy and security: Apple and Google announce industry specification for unwanted tracking
Mobile VRP divides applications into three tiers based on user data or association with Google services. Each tier has a corresponding reward amount, which varies depending on the vulnerability type and exploitation scenario.
At Tier 1, maximum rewards range from $750 for MiTM (man-in-the-middle) scenarios with theft of sensitive data to $30,000 for ACE vulnerabilities with no remote/user interaction.
“The Commission may, for example, apply a $1,000 bonus at its discretion for particularly surprising vulnerabilities or exceptional articles,” the program rules read.
Google clarified that only apps published by developers included in the new list or included in the Tier 1 list are eligible for the reward. However, the company acknowledged that other flaws could be eligible for a bounty if they demonstrate a security impact.
Google said it wants to maintain users’ trust and protect sensitive data by rewarding them for their contributions.
“Mobile VRP recognizes the contributions and hard work of researchers who have helped improve the security posture of Google’s first-party Android applications,” the post reads.
“The goal of this program is to mitigate vulnerabilities in first-party Android applications and keep users and their data safe.”
Mobile VRP comes a few weeks after Google announced a new policy against Android apps that allow account creation.
Editorial image credit: Primakov / Shutterstock.com