Friday , May 9 2025

“Google’s Temporary Offer: $180,000 Reward for Full Chain Chrome Exploit”

Google is temporarily offering a triple reward to bug bounty hunters who report functional full-chain exploits that can escape the Chrome browser’s sandbox. The bonus is effective until December 1, 2023.

A sandbox is a security feature that isolates code from the rest of the system, making it more difficult for attackers to exploit vulnerabilities. A full-chain exploit is a series of vulnerabilities that can be chained together to escape the sandbox and gain control of the system.

Microsoft Patches Four Critical Azure and Power Apps Vulns

Microsoft has fixed critical vulnerabilities in its core cloud services, including Azure Automation, Azure Storage, Azure DevOps, and Microsoft Power...
Read More
Microsoft Patches Four Critical Azure and Power Apps Vulns

Qilin Ransomware topped April 2025 with 45+ data leak disclosures

The cyber threat landscape is rapidly changing, with a notable increase in ransomware activity in April 2025, driven by the...
Read More
Qilin Ransomware topped April 2025 with 45+ data leak disclosures

SonicWall Patches 3 Flaws in SMA 100 Devices

SonicWall has released patches for three security flaws in SMA 100 Secure Mobile Access appliances that could allow remote code...
Read More
SonicWall Patches 3 Flaws in SMA 100 Devices

Top Ransomware Actively Attacking Financial Sector: 406 Incidents Disclosed

From April 2024 to April 2025, Flashpoint analysts noted that the financial sector was a major target for threat actors,...
Read More
Top Ransomware Actively Attacking Financial Sector: 406 Incidents Disclosed

Critical (CVSS 10) Flaw in Cisco IOS XE WLCs Allows RRA

Cisco has issued a security advisory for a critical vulnerability in its IOS XE Software for Wireless LAN Controllers (WLCs)....
Read More
Critical (CVSS 10) Flaw in Cisco IOS XE WLCs Allows RRA

CVE-2025-29824
Play Ransomware Exploited Windows CVE-2025-29824 as Zero-Day

Attackers linked to the Play ransomware operation deployed a zero-day privilege escalation exploit during an attempted attack against an organization...
Read More
CVE-2025-29824  Play Ransomware Exploited Windows CVE-2025-29824 as Zero-Day

Hacker exploited Samsung MagicINFO 9 Server RCE flaw

Hackers are exploiting an unauthenticated remote code execution vulnerability in the Samsung MagicINFO 9 Server to take control of devices...
Read More
Hacker exploited Samsung MagicINFO 9 Server RCE flaw

CISA adds Langflow flaw to its KEV catalog

CISA added the Langflow vulnerability, CVE-2025-3248 (CVSS score 9.8), to its Known Exploited Vulnerabilities catalog. Langflow is a popular tool...
Read More
CISA adds Langflow flaw to its KEV catalog

Google Fixes Android Flaw (CVE-2025-27363) Exploited by Attackers

Google has released its monthly Android security updates, addressing 46 vulnerabilities, including one that has been actively exploited. CVE-2025-27363 (CVSS...
Read More
Google Fixes Android Flaw (CVE-2025-27363) Exploited by Attackers

UAP hosted “UAP Cyber Siege 2025”, A national level cybersecurity competition

The Cyber Security Club, representing the Department of Computer Science and Engineering at the University of Asia Pacific (UAP), has...
Read More
UAP hosted “UAP Cyber Siege 2025”, A national level cybersecurity competition

Google is offering the bonus to encourage security researchers to find and report these types of vulnerabilities. By identifying and fixing these vulnerabilities, Google can make Chrome more secure and protect users from attack.

To be eligible for the bonus, the exploit must meet the following criteria:

  • It must be functional and work against Extended Stable, Stable, or Beta releases of Chrome.
  • It must result in a Chrome browser sandbox escape, with a demonstration of attacker control or code execution outside of the sandbox.
  • The exploit scenario must be fully remote and the exploit must be able to be used by a remote attacker.

In addition to the triple reward, Google is also offering a significant bonus for subsequent full-chain exploits submitted through the Chrome Vulnerability Reward Program (VRP). This bonus will double the regular reward.

ALSO READ:

Digital Bank in Bangladesh to Use AI Detect Fake Loans

By submitting a full chain exploit, participants could get a reward reaching as high as $180,000, potentially further augmented by other bonuses, and up to $120,000 for other exploits received throughout the rest of the six-month submission window.

“These exploits provide us valuable insight into the potential attack vectors for exploiting Chrome, and allow us to identify strategies for better hardening specific Chrome features and ideas for future broad-scale mitigation strategies,” said Amy Ressler, a Chrome Security Team Senior Technical Program Manager.

Google has been running the VRP since 2010, and has paid out over $50 million in bounties to researchers who have reported over 15,000 vulnerabilities. Last year alone, Google paid out $12 million, with a record-breaking $605,000 reward to gzobqq for a series of five security bugs part of an Android exploit chain.

The VRP is one of the ways that Google works to keep Chrome secure. By encouraging security researchers to find and report vulnerabilities, Google can make Chrome more secure for everyone.

Check Also

SK Telecom

South Korea’s largest SK Telecom Hit by Malware: SIM-related info leaked

South Korea’s largest mobile operator, SK Telecom, is warning that a malware infection allowed threat …

Leave a Reply

Your email address will not be published. Required fields are marked *