Android Bug Hunter Awarded Over $100,000 for Exposing Security Flaw in Google Pixel

Advertisement
By Sumit Chakraborty | Updated: 18 January 2018 18:37 IST
Highlights
  • Researcher rewarded under Android Security, Chrome Rewards programmes
  • Researcher submitted the exploit chain in August 2017
  • Issues resolved as part of the December 2017 monthly security update

Google has awarded $112,500 (roughly Rs. 71,83,300) to a security researcher for exposing a security flaw in Google Pixel smartphones. Guang Gong, in August 2017 submitted an exploit chain through the Android Security Rewards (ASR) programme. It was the first working remote exploit chain since the search giant has expanded the ASR program. Gong was awarded $105,000 (roughly Rs.  67,04,40), which Google claims is the highest reward in the ASR programme's history. Additionally, she was awarded $7,500 (roughly Rs. 4,78,900) under the Chrome Rewards program as well.

The technical details of the exploit were revealed by Google on its Android Developer's blog on Wednesday. The search giant thanked Gong, who is from Alpha Team, Qihoo 360 Technology, and the entire researcher community for finding and responsibly reporting security vulnerabilities. Meanwhile, Google said the complete set of issues was resolved as part of the December 2017 monthly security update, which patched a total of 42 bugs.

The exploit chain covers two bugs - CVE-2017-5116 and CVE-2017-14904. While the first one is a V8 engine bug that is used to get remote code execution in sandboxed Chrome render process the latter is is a bug in Android's libgralloc module that is used to escape from Chrome's sandbox. Google says this exploit chain can be used to inject arbitrary code into system_server by accessing a malicious URL in Chrome.

Advertisement

Google, through the Android Security Rewards programme, recognises the contributions of security researchers working on Android's security features. As of October 2017, the smartphones covered under the program include Google Pixel 2, Google Pixel and Pixel XL, and Google Pixel C.

Advertisement

In June 2017, Google had increased the ASR payout rewards for remote exploit chain or exploits leading to TrustZone or Verified Boot compromise from $50,000 (roughly Rs. 31,92,600
) to $200,000 (roughly Rs. 1,27,70,300). Through this program, Google has awarded researchers over $1.5 million (roughly Rs. 9,57,77,200) to date, with the top research team earning $300,000 (roughly Rs. 1,91,55,450)for 118 vulnerability reports.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Cloudflare Is Down Again For the Second Time in Weeks: See Affected Sites
  2. ACT Fibernet Launches New Broadband Plans With Free OTT Subscriptions
  3. Nothing Phone 3a Lite Goes on Sale in India at This Price
  4. OnePlus 15R Surfaces on Benchmarking Site Ahead of India Launch
  5. HMD 101, HMD 100 With Built-In Radio Launched in India at These Prices
  6. Airtel Discontinues These Prepaid Recharge Packs in India
  7. Vivo S50 Colour Options, Key Features Surface Online Ahead of Launch
  8. Motorola Edge 70 With Pantone's 2026 Colour, Swarovski Crystals Launched
  9. Flipkart Buy Buy 2025 Sale: Nothing Phone 3, Phone 3a Deals Revealed
  10. Instamart to Provide 10-Minute Delivery of Samsung Galaxy Devices
  1. Google’s Year in Search 2025: Top Trending Topics in India—From Gemini to Squid Games
  2. Vivo S50 Colour Options, Key Features Surface Online; Could Launch in India as Vivo V70
  3. CFTC Clears Path for Spot Crypto Trading on Regulated Platforms for the First Time
  4. Cloudflare Outage Blocks Access to Several Websites Including BookMyShow, SpaceX, Coinbase
  5. Samsung Galaxy S26 Series to Offer Built-In Support for Company's 25W Magnetic Qi2 Charger: Report
  6. Airtel Discontinues Two Prepaid Recharge Packs in India With Data Benefits, Free Airtel Xtreme Play Subscription
  7. Samsung Galaxy Phones, Devices Are Now Available via Instamart With 10-Minute Instant Delivery
  8. NotebookLM App Gets an In-Built Camera, Lets Users Upload Images as a Source
  9. HMD 101 Launched in India With 1,000mAh Battery, Auto Call Recording Alongside HMD 100: Price, Features
  10. Crypto Traders Await US Fed Signals as Bitcoin Price Drops to $91,900
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.