SinfrasSinfras
Aa
  • Home
  • Diet
  • Gadgets
  • Sports
  • Education
  • Social Media
  • Clothing
  • News
  • Contact Us!
  • Privacy Policy
Reading: Android Bug Hunter Awarded Over $100,000 for Exposing Security Flaw in Google Pixel
Share
Aa
SinfrasSinfras
Search
  • Home
  • Diet
  • Gadgets
  • Sports
  • Education
  • Social Media
  • Clothing
  • News
  • Contact Us!
  • Privacy Policy
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Sinfras > Gadgets > Android Bug Hunter Awarded Over $100,000 for Exposing Security Flaw in Google Pixel
Gadgets

Android Bug Hunter Awarded Over $100,000 for Exposing Security Flaw in Google Pixel

Loknath Das
Last updated: 2018/01/18 at 5:04 PM
By Loknath Das 2 Min Read
Share

Android Bug Hunter Awarded Over $100,000 for Exposing Security Flaw in Google Pixel

Google has awarded $112,500 (roughly Rs. 71,83,300) to a security researcher for exposing a security flaw in Google Pixel smartphones. Guang Gong, in August 2017 submitted an exploit chain through the Android Security Rewards (ASR) programme. It was the first working remote exploit chain since the search giant has expanded the ASR program. Gong was awarded $105,000 (roughly Rs.  67,04,40), which Google claims is the highest reward in the ASR programme’s history. Additionally, she was awarded $7,500 (roughly Rs. 4,78,900) under the Chrome Rewards program as well.

The technical details of the exploit were revealed by Google on its Android Developer’s blog on Wednesday. The search giant thanked Gong, who is from Alpha Team, Qihoo 360 Technology, and the entire researcher community for finding and responsibly reporting security vulnerabilities. Meanwhile, Google said the complete set of issues was resolved as part of the December 2017 monthly security update, which patched a total of 42 bugs.

The exploit chain covers two bugs – CVE-2017-5116 and CVE-2017-14904. While the first one is a V8 engine bug that is used to get remote code execution in sandboxed Chrome render process the latter is is a bug in Android’s libgralloc module that is used to escape from Chrome’s sandbox. Google says this exploit chain can be used to inject arbitrary code into system_server by accessing a malicious URL in Chrome.

Google, through the Android Security Rewards programme, recognises the contributions of security researchers working on Android’s security features. As of October 2017, the smartphones covered under the program include Google Pixel 2, Google Pixel and Pixel XL, and Google Pixel C.

In June 2017, Google had increased the ASR payout rewards for remote exploit chain or exploits leading to TrustZone or Verified Boot compromise from $50,000 (roughly Rs. 31,92,600
) to $200,000 (roughly Rs. 1,27,70,300). Through this program, Google has awarded researchers over $1.5 million (roughly Rs. 9,57,77,200) to date, with the top research team earning $300,000 (roughly Rs. 1,91,55,450)for 118 vulnerability reports.

 

 

[“source=gadgets.ndtv”]

Share this:

  • Reddit
  • Tweet
  • Share on Tumblr
  • WhatsApp
TAGGED: $100000, Android, Awarded, Bug, Exposing, Flaw, For, Google, Hunter, in, Over, Pixel, Security
Loknath Das January 18, 2018
By Loknath Das
I am a blogger with the main motive of writing articles at my choice of level. I do love to write articles and keep my website updated regularly , if you love my article then be sure to share with your friends as they would love to read my article...
Previous Article Honor View 10 Gets Improved Face Unlock Features and More With New OTA Update
Next Article Sony Xperia XZ Pro With 18:9 Display, Snapdragon 845 Expected at MWC 2018: Report

Latest News

The Role of Artificial Intelligence (AI) in K-12 Professional Development
Education
For information seekers, social media is junk food
Social Media
How Google and YouTube are providing ongoing wildfire relief to greater Los Angeles students and teachers
Education
motorola edge 50 with 6.67″ 1.5K pOLED curved display, military-grade durability launching in India on August 1
News

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?