Google to pay $200,000 in hunt for Android bugs

Most security flaws affect the older versions of the OS

June 03, 2017 10:50 pm | Updated 10:50 pm IST - New York

Bug bounties help anticipate virus attacks.

Bug bounties help anticipate virus attacks.

Days after a malware called “Judy” hit over 36.5 million Android-based phones, Google has now increased the bounty for finding a bug in the Android operating system to as much as $200,000, a media report has said.

According to cyber security firm Check Point, dozens of malicious apps were downloaded between 4.5 million to 18.5 million times from the Play Store. Some of the malware-affected apps have been discovered residing on the online store for several years.

“Judy” is only one example of how an open and free mobile operating system (OS) can be exploited by malicious app developers.

Most security flaws we hear about now affect old versions of the OS or require clever social engineering to get the user to weaken device security, technology website extremetech.com reported.

New versions secure

The versions of Android being released now are more secure than what Google was putting out years ago and as a result no one has managed to claim Google’s largest bug bounties for Android.

Hoping to attract more researchers and engineers to the bug bounty programme, the company has increased the rewards to up to $200,000.

Google started the bug bounty programme for Android about two years ago in which the security researchers, who can find a flaw, get a cash prize — the amount of which varies based on the severity of the hack.

Then, Google gets to fix the bug and avoid future security issues.

Still, no one has submitted a working exploit for Android’s core components, even when such an exploit is worth $30,000—$50,000, the report said.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.