{"id":6298,"date":"2019-09-06T14:15:00","date_gmt":"2019-09-06T14:15:00","guid":{"rendered":"https:\/\/gtechbooster.com\/?p=6298"},"modified":"2023-04-01T01:36:50","modified_gmt":"2023-04-01T01:36:50","slug":"google-bug-bounty-gets-to-third-party-apps","status":"publish","type":"post","link":"https:\/\/gtechbooster.com\/google-bug-bounty-gets-to-third-party-apps\/","title":{"rendered":"Google bug bounty gets to Third Party Apps"},"content":{"rendered":"\n<p>Google is extending its bug bounty scheme to third party apps in the \nGoogle Play Store. The reward will apply to problems found in any app \nthat has more than 100 million installs.<\/p>\n\n\n\n<div class=\"gtech-migrated-from-ad-inserter-placement-2\" style=\"text-align: center;\" id=\"gtech-3004608813\"><div style=\"margin-left: auto;margin-right: auto;text-align: center;\" id=\"gtech-2874305017\"><a data-bid=\"1\" data-no-instant=\"1\" href=\"https:\/\/gtechbooster.com\/linkout\/78935\" rel=\"noopener\" class=\"notrack\" aria-label=\"auyvc003\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gtechbooster.com\/media\/2026\/03\/auyvc003.webp\" alt=\"\"  srcset=\"https:\/\/gtechbooster.com\/media\/2026\/03\/auyvc003.webp 1200w, https:\/\/gtechbooster.com\/media\/2026\/03\/auyvc003-768x768.webp 768w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" width=\"500\" height=\"500\"  style=\"display: inline-block;\" \/><\/a><\/div><\/div><p>The increase is being made as part of the Google Play Security Reward  Program (GPSRP), and Google is also launching a new Developer Data  Protection Reward Program (DDPRP).<\/p>\n\n\n\n<p>So long as an app has enough installs, if a bug is found in it the \nfinder will be eligible for a reward, even if the app developers don\u2019t \nhave their own vulnerability disclosure or bug bounty program. If that&#8217;s\n the case, Google helps responsibly disclose identified vulnerabilities \nto the affected app developer. If the developers already have their own \nprograms, researchers can collect rewards directly from them on top of \nthe rewards from Google.<\/p>\n\n\n\n<p>Google says it uses vulnerability data from GPSRP to create automated\n checks that scan all apps available in Google Play for similar \nvulnerabilities. Over the lifetime of the App Security Improvement (ASI)\n program, it has helped more than 300,000 developers fix more than \n1,000,000 apps on Google Play.<\/p>\n\n\n\n<p>The news of the extension to the scheme follows an announcement by \nGoogle in July that the maximum baseline reward amount was being raised \nfrom $5,000 to $15,000 for Chrome bugs, and the amount for high-quality \nreports from $15,000 to $30,000.<\/p>\n\n\n\n<p>Google has also launched a Developer Data Protection Reward Program.  DDPRP is a bounty program that&#8217;s aimed at identifying and mitigating  data abuse issues in Android apps, OAuth projects, and Chrome  extensions. The program aims to identify situations where user data is  being used or sold unexpectedly, or repurposed in an illegitimate way  without user consent. If data abuse is identified related to an app or  Chrome extension, that app or extension will be removed from Google Play  or Google Chrome Web Store, and if an app developer is abusing access  to Gmail restricted scopes, their API access will be removed. Google  hasn&#8217;t so far published a reward table or maximum reward, but the  announcement said that depending on impact, a single report could  qualify for a reward as large as $50,000.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">More Information<\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/hackerone.com\/googleplay\">Google Play Security Reward Program<\/a><\/li><li><a href=\"https:\/\/hackerone.com\/ddp_reward_program\">Developer Data Protection Reward Program<\/a><\/li><\/ul>\n<div class=\"gtech-end-cont\" id=\"gtech-2998176987\"><div style=\"margin-right: auto;margin-left: auto;text-align: center;\" id=\"gtech-531566627\"><a data-bid=\"1\" data-no-instant=\"1\" href=\"https:\/\/gtechbooster.com\/linkout\/17207\" rel=\"noopener\" class=\"notrack\" aria-label=\"26001\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gtechbooster.com\/media\/2023\/01\/26001.jpeg\" alt=\"\"  srcset=\"https:\/\/gtechbooster.com\/media\/2023\/01\/26001.jpeg 1024w, https:\/\/gtechbooster.com\/media\/2023\/01\/26001-768x960.jpeg 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" width=\"500\" height=\"625\"  style=\"display: inline-block;\" \/><\/a><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>Google is extending its bug bounty scheme to third party apps in the Google Play Store. The reward will apply to problems found in any app that has more than 100 million installs. The increase is being made as part of the Google Play Security Reward Program (GPSRP), and Google is also launching a new [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":6299,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1915],"tags":[64,993,372,6],"class_list":["post-6298","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ndocs","tag-android","tag-bug-bounty-program","tag-google","tag-programming"],"blocksy_meta":{"styles_descriptor":{"styles":{"desktop":"","tablet":"","mobile":""},"google_fonts":[],"version":6}},"_links":{"self":[{"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/posts\/6298","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/comments?post=6298"}],"version-history":[{"count":0,"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/posts\/6298\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/media\/6299"}],"wp:attachment":[{"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/media?parent=6298"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/categories?post=6298"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/tags?post=6298"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}