Google is extending its bug bounty scheme to third party apps in the Google Play Store. The reward will apply to problems found in any app that has more than 100 million installs.
The increase is being made as part of the Google Play Security Reward Program (GPSRP), and Google is also launching a new Developer Data Protection Reward Program (DDPRP).
So long as an app has enough installs, if a bug is found in it the finder will be eligible for a reward, even if the app developers don’t have their own vulnerability disclosure or bug bounty program. If that’s the case, Google helps responsibly disclose identified vulnerabilities to the affected app developer. If the developers already have their own programs, researchers can collect rewards directly from them on top of the rewards from Google.
Google says it uses vulnerability data from GPSRP to create automated checks that scan all apps available in Google Play for similar vulnerabilities. Over the lifetime of the App Security Improvement (ASI) program, it has helped more than 300,000 developers fix more than 1,000,000 apps on Google Play.
The news of the extension to the scheme follows an announcement by Google in July that the maximum baseline reward amount was being raised from $5,000 to $15,000 for Chrome bugs, and the amount for high-quality reports from $15,000 to $30,000.
Google has also launched a Developer Data Protection Reward Program. DDPRP is a bounty program that’s aimed at identifying and mitigating data abuse issues in Android apps, OAuth projects, and Chrome extensions. The program aims to identify situations where user data is being used or sold unexpectedly, or repurposed in an illegitimate way without user consent. If data abuse is identified related to an app or Chrome extension, that app or extension will be removed from Google Play or Google Chrome Web Store, and if an app developer is abusing access to Gmail restricted scopes, their API access will be removed. Google hasn’t so far published a reward table or maximum reward, but the announcement said that depending on impact, a single report could qualify for a reward as large as $50,000.