Google Expands Scope of Its Bug Bounty Programme, Unveils Data Protection Reward Programme for Developers

The Data Protection Reward Program for Developers covers Android apps, OAuth projects, and Chrome extensions

Advertisement
By Nadeem Sarwar | Updated: 30 August 2019 13:45 IST
Highlights
  • Apps whose developers don’t run a bounty program are covered too
  • DDPRP covers Android apps, OAuth projects, and Chrome extensions
  • It can net a reward as big as $50,000 (roughly Rs. 36,80,000)

The program will no longer mandate a developer having its own vulnerability report channel

It appears that the recent surge in the number of malware-loaded apps that have managed to rake millions of downloads have forced Google to reconsider its data security strategy. To effectively handle the threats, Google has widened the scope of its Google Play Security Reward Program (GPSRP) to cover all apps that have amassed over 100 million downloads on the Play Store. This effectively means Google is providing a bug bounty for finding vulnerabilities in third-party apps. Additionally, the company has also launched the Developer Data Protection Reward Program (DDPRP) in collaboration with HackerOne to discover and eliminate data abuse issues spotted in Android apps, OAuth projects, and Chrome extensions.

Google has actively been purging malware-laden apps from the Play Store, but the company has been having a hard time with it, especially when some very popular apps are found to be complicit. Take for example the CamScanner app, which had over 100 million downloads, but was recently booted from the Play Store for seeding an advertising malware. To more effectively curb such instances, Google has expanded its Google Play Security Reward Program (GPSRP) to cover all apps that have clocked 100 million or more downloads on the Play Store.

Security researchers can now collect bounty for discovering vulnerabilities and serious security bugs in eligible apps, even if the developers are not running a bug bounty programme. And in case a developer-side bug bounty programme exists, researchers can collect rewards from them as well as Google as an added incentive. As for the rewards, finding a RCE (Remote Code Execution) vulnerability will pocket the security researcher a cool $20,000 (roughly Rs. 14,31,000). Discovery of vulnerabilities that lead to data theft will be rewarded with $3,000 (roughly Rs. 2,15,000), while those that concern access to a protected app component will net the finder an equivalent amount.

Advertisement

In addition to tweaking the bug bounty programme, Google has also unveiled the Developer Data Protection Reward Program (DDPRP) in collaboration with HackerOne. The goal of DDRP is to “identify and mitigate data abuse issues in popular Android applications, OAuth projects, and Chrome extensions”. Under the aegis of DDPRP, Google will reward developers who find apps that violate Google Play, Google API or the Google Chrome Web Store programme policies.

Advertisement

Apps that mishandle local phone data, those that share sensitive information with third-party advertisers, an extension that violates Chrome Web Store's minimum user data privacy requirements, are among the instances that Google wants to identify and eliminate. 

In case data abuse is spotted, the app or Chrome extension will duly be removed from the Play Store and the Google Chrome Web Store. On a similar note, involvement in abusing access to Gmail restricted scopes will result in the removal of API access. A peak reward is yet to be listed, but security researchers can expect to net a bounty as large as $50,000 (roughly Rs. 36,80,000) if the discovery is really impactful 

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo V70 Elite, Vivo V70 Will Launch in India on This Date
  2. Samsung Galaxy A07 5G With 6,000mAh Battery Launched in India: See Price
  3. Asus Launches New Zenbook and Vivobook Laptops in India: See Prices, Offers
  4. Realme P4 Power 5G With 10,001mAh Battery Goes on Sale in India
  5. OTT Releases of the Week: The Raja Saab, Kis Kisko Pyaar Karoon 2, Parasakthi, and More
  6. Anthropic Mocks ChatGPT in New Ads, OpenAI CEO Calls Them 'Deceptive'
  7. Apple's Low-Cost MacBook Could Be Powered by a Chip From This iPhone
  8. Oppo Find N6, Honor Magic V6 Could Launch With Advanced Stylus Support
  9. Xiaomi 17 Ultra Global Variant Spotted in New Leak That Shows Its Display Design
  10. Super Subbu OTT Release Confirmed: Everything You Need to Know
  1. James Webb Telescope Discovers Most Distant Galaxy From Just 300 Million Years After the Big Bang
  2. Ikka Starring Sunny Deol and Akshay Khanna to Stream Soon on Netflix: What You Need to Know
  3. Blue Origin Halts New Shepard Space Tourism for at Least Two Years
  4. YouTube’s Auto-Dubbing Is Now Available to All Users With 27 Supported Languages, New Features
  5. Oppo Find X9s to Launch in Global Markets Including India With MediaTek Dimensity 9500s SoC: Report
  6. iQOO Z11 5G, iQOO Z11 Lite 5G Reportedly Listed on IMEI Database Ahead of Anticipated Debut
  7. Faraday Future Launches its First Series of Multipurpose AI-Powered Humanoid and Bionic Robots
  8. Oppo Reno 15c 5G With 7,000mAh Battery, 50-Megapixel Camera Goes on Sale in India: Price, Offers
  9. Sony Sells 8 Million PS5 Units in Q3 FY 2025, Reports 19 Percent PlayStation Profit Growth
  10. Overwatch 2 Rebrands to 'Overwatch' as Blizzard Announces 10 New Heroes, Year-Long Story, Switch 2 Version
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.