{"id":39496,"date":"2019-08-21T09:09:40","date_gmt":"2019-08-21T09:09:40","guid":{"rendered":"http:\/\/icloud.pe\/blog\/?guid=79c851a958d4e5abaae2b5726048522d"},"modified":"2019-08-21T09:09:40","modified_gmt":"2019-08-21T09:09:40","slug":"microsoft-launches-bug-bounty-programme-chromium-based-edge","status":"publish","type":"post","link":"https:\/\/icloud.pe\/blog\/microsoft-launches-bug-bounty-programme-chromium-based-edge\/","title":{"rendered":"Microsoft launches bug bounty programme Chromium-based Edge"},"content":{"rendered":"<p><span class=\"field field-name-field-author field-type-node-reference field-label-hidden\"><br \/>\n      <span class=\"field-item even\"><a href=\"https:\/\/www.cloudpro.co.uk\/authors\/connor-jones\">Connor Jones<\/a><\/span><br \/>\n  <\/span><\/p>\n<div class=\"field field-name-field-published-date field-type-datetime field-label-hidden\">\n<div class=\"field-items\">\n<div class=\"field-item even\"><span class=\"date-display-single\">21 Aug, 2019<\/span><\/div>\n<\/p><\/div>\n<\/div>\n<p class=\"short-teaser\">\n<a href=\"https:\/\/www.cloudpro.co.uk\/\" title=\"\" class=\"combined-link\"><\/a><\/p>\n<div class=\"field field-name-body\">\n<p> <a href=\"https:\/\/www.cloudpro.co.uk\/cloud-essentials\/public-cloud\/8115\/local-or-microsoft-account-which-is-best-for-you\" >Microsoft<\/a> has launched a fresh bug bounty programme specifically for its Chromium-based Edge browser, offering rewards double the value of its previous HTML Edge version.<\/p>\n<p>The maximum reward for hunters finding significant flaws in the latest version of its flagship browser has increased to $30,000 for the most critical vulnerabilities.<\/p>\n<p>Other issues will be judged by their significance, depending on how impactful the flaw is to future versions of Edge, with hunters being rewarded from $1,000 upwards.<\/p>\n<p>The launch of the latest bug bounty programme coincides with the launch of the beta preview of the next Edge version and will work hand-in-hand with Microsoft&#8217;s Researcher Recognition Program.<\/p>\n<p>The initiative acts somewhat like a loyalty card for bug hunters who follow Microsoft&#8217;s vulnerability disclosure process: Points are awarded for every bug they report and these points can be multiplied depending on the product on which they&#8217;re found.<\/p>\n<p>A bug found in <a href=\"https:\/\/www.cloudpro.co.uk\/cloud-essentials\/public-cloud\/8163\/microsoft-azure-review-competitive-cloud-pricing-takes-a-bite-out\" >Azure<\/a> or <a href=\"https:\/\/www.cloudpro.co.uk\/leadership\/cloud-essentials\/7965\/microsoft-launches-cloud-native-security-management-tool-azure\" >Windows Defender<\/a>, for example, is eligible for a 3x points multiplier whereas Edge on Chromium gets a mere 2x multiplier \u2013 GitHub and LinkedIn receive none.<\/p>\n<p>Once a hunter accrues enough points, they &#8220;may be recognised in our public leaderboard and rankings, annual Most Valuable MSRC Security Researcher list, and invited to participate in exclusive events and programs,&#8221;\u00a0said Microsoft.<\/p>\n<p>The program will also run alongside the pre-existing bug bounty for the HTML version of Edge, which offers rewards of between $500 &#8211; $15,000.<\/p>\n<p>&#8220;Vulnerabilities that reproduce in the latest, fully patched version of Windows (including <a href=\"https:\/\/www.cloudpro.co.uk\/cloud-essentials\/public-cloud\/8115\/local-or-microsoft-account-which-is-best-for-you\" >Windows 10<\/a>, Windows 7 SP1 or Windows 8.1) or MacOS may be eligible for the Microsoft Edge Insider bounty program,&#8221; said Microsoft. &#8220;Windows Insider Preview is not required.&#8221;<\/p>\n<p>Since the browser is powered using Chromium, the new bug bounty programme will support the Chrome Vulnerability Reward Program &#8220;so any report that reproduces on the latest version of Microsoft Edge but not Chrome will be reviewed for bounty eligibility based on severity, impact, and report quality,&#8221; it added.<\/p>\n<p>The Chrome Vulnerability Reward Program currently offers rewards ranging vastly from $500 to $150,000 with the greatest rewards likely to be issued for bugs found in Chrome OS.<\/p>\n<p>Apple also announced the expansion of its bug bounty programme at Black Hat 2019 in August, making it the most lucrative bounty program in tech.<\/p>\n<p>In addition to dishing out special iPhones to select bug hunters, making it easier for them to investigate the flagship Apple device, it announced a\u00a0<a href=\"https:\/\/www.itpro.co.uk\/security\/34185\/security-researchers-now-eligible-for-bug-hunting-iphones\" >maximum reward for bugs of up to $1.5 million<\/a>.<\/p>\n<p>Back in March, an Argentinian teenage bug hunter became the\u00a0<a href=\"https:\/\/www.itpro.co.uk\/bugs\/33127\/teenage-hacker-makes-1m-from-bug-bounty-rewards\" >first in the world to earn $1 million<\/a>\u00a0from lawfully finding and disclosing bugs in bounty programs. He reported more than 1,600 bugs \u2013 notable inclusions were major issues with Twitter&#8217;s and Verizon&#8217;s products. <\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>      Connor Jones<\/p>\n<p>        21 Aug, 2019    <\/p>\n<p>       Microsoft has launched a fresh bug bounty programme specifically for its Chromium-based Edge browser, offering rewards double the value of its previous HTML Edge version.<br \/>\nThe maximum reward for&#8230;<\/p>\n","protected":false},"author":507,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-39496","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/39496","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/users\/507"}],"replies":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/comments?post=39496"}],"version-history":[{"count":3,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/39496\/revisions"}],"predecessor-version":[{"id":39503,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/39496\/revisions\/39503"}],"wp:attachment":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/media?parent=39496"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/categories?post=39496"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/tags?post=39496"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}