Critical Vulnerabilities Allowed Booking.com Account Takeover

Security researchers discovered recently that the online travel agency Booking.com was impacted by serious vulnerabilities that could have been exploited to take complete control of a user’s account.

The issues were identified by API security firm Salt Security and reported to Booking.com in early December 2022. Patches were rolled out in the next few weeks and Salt Security disclosed technical details on Thursday.

The vulnerabilities found by Salt Security researchers centered around the way Booking.com implemented OAuth, the authorization standard used by many online services to allow customers to sign in with their Google or Facebook accounts.

In the case of Booking.com, the flaws were related to the OAuth integration with Facebook. An attacker could have exploited these weaknesses to take complete control of a user’s account, obtain their personal information from their Booking account, and perform actions on the victim’s behalf, such as canceling or booking reservations and ordering transportation services.

The issue also impacted Booking.com sister website Kayak.com, which allows users to log in using their Booking account. 

In order to exploit these vulnerabilities, an attacker would have needed to trick the targeted user into clicking on a specially crafted link. This would allow the hacker to capture a logged-in user’s authentication code for Booking.com by abusing the OAuth login mechanism. 

The attacker would then need to access their own Booking.com account from a mobile application. However, in the authentication request sent by the mobile app to the Booking server, they needed to replace their own code with the victim’s code. This would give them full access to the victim’s account. 

Salt Security believes millions of users may have been exposed to potential attacks exploiting these vulnerabilities. 

The security firm has made a video showing the exploit in action:

[embedded content]

Related: Critical Account Takeover Vulnerability Patched in GitLab Enterprise Edition

Related: Multi-Factor Authentication Bypass Led to Box Account Takeover

Related: Facebook Pays Out $40,000 for Account Takeover Exploit Chain

Critical Vulnerabilities Allowed Booking.com Account Takeover




Cisco Patches Critical Vulnerability in IP Phones

Cisco this week announced software updates that address a critical vulnerability in the web-based management interface of its 6800, 7800, and 8800 series IP phones.

Tracked as CVE-2023-20078 (CVSS score of 9.8), the issue can be exploited by an unauthenticated, remote attacker to execute code with root privileges.

The security defect, Cisco explains in its advisory, exists because user input is not sufficiently validated.

“An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system of an affected device,” the tech giant explains.

Vulnerable products include IP Phone 6800, 7800, and 8800 series devices, with multiplatform firmware. The flaw was addressed with the release of firmware version 11.3.7SR1.

The firmware update also addresses CVE-2023-20079 (CVSS score of 7.5), another insufficient validation of user-provided input bug, which could be exploited to cause a denial-of-service (DoS) condition.

In addition to the aforementioned devices, the vulnerability also impacts Cisco’s unified IP conference phone 8831, unified IP conference phone 8831 with multiplatform firmware, and unified IP phone 7900 series devices, which have reached end-of-life (EoL) status and will not receive patches.

Cisco says it is not aware of any of these vulnerabilities being exploited in malicious attacks.

This week, the tech giant also released software updates that resolve medium-severity vulnerabilities in Webex App for Web, Finesse, and Prime Infrastructure and Evolved Programmable Network (EPN) Manager.

The company also announced that it was working on patches for two medium-severity issues impacting Unified Intelligence Center. Version 12.6(2) of Unified Intelligence Center, expected to arrive in March, will address both flaws.

Additional information can be found on Cisco’s product security page.

Related: Cisco Patches High-Severity Vulnerabilities in ACI Components

Related:Critical Vulnerability Patched in Cisco Security Products

Related: Flaw in Cisco Industrial Appliances Allows Malicious Code to Persist Across Reboots

https://www.securityweek.com/cisco-patches-critical-vulnerability-in-ip-phones/




Top 10 Security, Operational Risks From Open Source Code

Endor Labs has introduced an OWASP-style listing of the most important or impactful risks inherent in the use of open source software (OSS).

Use of OSS is effectively free and readily available – it satisfies the commercial need for speed at low cost in software development. It is not uncommon for more than 80% of modern application code to come from OSS, and it is therefore here to stay (at least until some new technology can provide faster yet still inexpensive software development).

The problem here is that we know very little about the source of the open source we use. It comes without warranties or SLAs; we are usually unaware of the developers of this development tool; and it can introduce major security risks (just think Log4J) without our awareness.

Endor Labs, a startup headquartered in Palo Alto, CA, and founded in 2021 by Dimitri Stiliadis (CTO) and Varun Badhwar (CEO), is a firm focused on the complexities and threats contained in the growing use of OSS in commercial application development.

Its Station 9 research team has now developed and published a report (PDF) on the Top Ten Open Source Software Risks. The hope is to emulate for OSS what the OWASP Top Ten provides for web application security. It lists the ten most important risks (security and/or ops) in order of severity, providing a description, examples, remediation and further reference sources. Like the OWASP list, it will be maintained as the individual risks change or are replaced in severity by new risks.

Unsurprisingly, the current #1 risk is ‘known vulnerabilities’. The Endor description states, “A component version may contain vulnerable code, accidentally introduced by its developers. Vulnerability details are publicly disclosed, for example, through a CVE. Exploits and patches may or may not be available.” Here it is worth noting Rapid7’s research pointing out that 56% of CVE vulnerabilities are exploited within seven days of the public disclosure.

The remaining nine risks are:

  • The compromise of a legitimate package, where attackers may for example inject malicious code to take advantage of a supply chain attack against users of that code
  • A name confusion attack, which is like typo-squatting in web-based attacks
  • Unmaintained software, where the component may unknowingly no longer be maintained or supported
  • Outdated software, where an old version is in use even though a newer version may be available,
  • Untracked dependencies, perhaps because it is not part of an upstream SBOM
  • License and regulatory risk, where – for example – the license may be incompatible with the intended use by a downstream consumer
  • Immature software, where the OSS project development may not conform to development best practices
  • Unapproved changes, where a component may change without the developers being aware
  • Under- or over-sized dependency, where, in the latter case, a component may provide a lot of functionality of which only a fraction may be used

There are, of course, many more than ten OSS risks. “We’ll probably refresh this list at least every year if things change. Some years, nothing will change; some years it will,” Badhwar told SecurityWeek.

You may think that the SBOM was introduced to solve these questions for application developers, but the SBOM is almost unique in being a regulation that is ahead of industry practices rather than behind them. “Industry isn’t ready for the SBOM,” Badwahr said. Automatic generation is usually inaccurate and incomplete. “We need to solve these problems if we are going to pivot toward using the SBOM as the indisputable source of truth for our risk analysis. That’s not the case today.”

It is also worth considering the fragility of the OSS ecosphere despite its importance to much of the commercial applications in use. Badwahr pointed to Core-JS. “Core-JS is a foundational bedrock of the internet. Pick any internet application and you can be certain it uses Core-JS.”

But Core-JS is maintained by Denis Pushkarev in Russia. He has made a relatively meagre living from it – until now. Financial contributions from the West into Russia have been hit by western monetary sanctions. According to a report in The Stack, he is being forced to consider alternatives, including making it closed source and commercial. 

The reality is that the sustainability of the OSS ecosphere depends upon the sustainability of its contributors, and this is as unpredictable as the future of geopolitics. It is Endor’s hope that the enumeration of the top OSS risks can help focus the minds of application developers on the risks involved in employing open source software – including suddenly unmaintained software (risk #4).

Related: Software Supply Chain Security Firm Lineaje Raises $7 Million

Related: Google Shells Out $600,000 for OSS-Fuzz Project Integrations

Related: Oligo Security Exits Stealth with $28M for AppSec, Open Source Security

Related: Vulnerability in Popular JsonWebToken Open Source Project Leads to Code Execution

https://www.securityweek.com/top-10-security-operational-risks-from-open-source-code/




Security Defects in TPM 2.0 Spec Raise Alarm

Security researchers at Quarkslab have identified a pair of serious security defects in the Trusted Platform Module (TPM) 2.0 reference library specification, prompting a massive cross-vendor effort to identify and patch vulnerable installations.

The vulnerabilities, tracked as CVE-2023-1017 and CVE-2023-1018, provide pathways for an authenticated, local attacker to overwrite protected data in the TPM firmware and launch code execution attacks, according to an advisory from Carnegie Mellon’s CERT coordination center. 

From the CERT alert:

“An authenticated, local attacker could send maliciously crafted commands to a vulnerable TPM allowing access to sensitive data. In some cases, the attacker can also overwrite protected data in the TPM firmware. This may lead to a crash or arbitrary code execution within the TPM. Because the attacker’s payload runs within the TPM, it may be undetectable by other components of the target device.”

“An attacker who has access to a TPM-command interface can send maliciously-crafted commands to the module and trigger these vulnerabilities. This allows either read-only access to sensitive data or overwriting of normally protected data that is only available to the TPM (e.g., cryptographic keys),” the center added.

Quarkslab researchers Francisco Falcon and Ivan Arce are credited with finding the bugs and leading an industry-wide coordinated vulnerability process ahead of Tuesday’s public advisory.

The Trusted Computing Group (TCG) responsible for maintaining the TPM spec has issued an Errata documenting the two memory corruption issues and providing mitigation guidance. 

The two vulnerabilities exist in the way the TPM reference spec processes parameters that are part of TPM commands. “An Out Of Bound (OOB) read vulnerability in the CryptParameterDecryption() routine allowed a 2-byte read access to data that was not part of the current session. It was also possible to write 2-bytes past the end of the current command buffer resulting in corruption of memory,” the center warned.

“An attacker with access to a device built with a vulnerable version of the TPM can trigger this bug by sending crafted commands to the TPM. The vulnerable TPM can thus be tricked to access data that is not part of the intended operation. As the OS relies on the TPM firmware for these functions, it may be difficult to detect or prevent such access using traditional host-based security capabilities,” it added.

This discovery has raised alarm bells because TPM technology is used in a variety of devices, from specialized enterprise-grade hardware to Internet of Things (IoT) appliances. With the growth of cloud computing and virtualization, software-based TPM implementations have also gained popularity. 

The CERT coordination center is urging users to apply any updates provided by hardware and software manufacturers through their supply chain as soon as possible.

“Updating the firmware of TPM chips may be necessary, and this can be done through an OS vendor or the original equipment manufacturer (OEM). In some cases, the OEM may require resetting the TPM to its original factory default values as part of the update process,” the center added.

In high-assurance computing environments, users should consider using TPM Remote Attestation to detect any changes to devices and ensure their TPM is tamper-proof. 

“As these attacks involve TPM-based software, mechanisms such as user-password or PIN protection and tpm-totp do not protect against attacks leveraging the [memory corruption]  vulnerabilities,” according to the advisory.

Related:  Two Dozen UEFI Vulnerabilities Impact Millions of Devices From Major Vendors

Related: Why it’s So Hard to Implement IoT Security

Related: Intel Announces New Hardware-based Security Capabilities

https://www.securityweek.com/security-defects-in-tpm-2-0-spec-raise-alarm-bells/




Vulnerabilities Being Exploited Faster Than Ever: Analysis

In 2022, the widespread exploitation of new vulnerabilities was down 15% over the previous year; zero-day attacks declined 52% from 2021; and there were 33% fewer vulnerabilities known to have been exploited as part of a ransomware attack. On the surface, it might appear that things were easier for security teams last year. That would be wrong.

The figures are taken from Rapid7’s 2022 Vulnerability Intelligence Report, an annual publication commenced in 2020. The most worrying finding today is the time from vulnerability disclosure to exploitation is decreasing. “A large number of vulnerabilities are being exploited before security teams have any time to implement patches or other mitigations,” Caitlin Condon, senior manager of security research at Rapid7, told SecurityWeek.

To be precise, 56% of the vulnerabilities in the report were exploited within seven days of public disclosure – a 12% increase over 2021, and an 87% increase over 2020. Resources for triaging and remediating vulnerabilities remain limited, and priorities can be misdirected.

A good example of this was hype emanating from Log4Shell. “Many organizations spent the first weeks (or months) of 2022 working their way down a lengthy list of Log4Shell remediations, taxing IT and security team resources that had already been depleted by shrinking budgets and pandemic exhaustion,” notes the report.

But after Log4Shell we had Spring4Shell and then Text4Shell. There was, suggests Condon, “a 4Shell cadence given to new vulnerabilities.” This implied they were of the same magnitude as Log4Shell when they were not. But the C-suite saw these reports and asked the security folks, what are we doing? “It’s kind of hard for the security team to reply, ‘yeah, it’s called 4Shell, but it’s stupid and we’re not prioritizing it,’” said Condon. The result is resources are inadvertently redirected from important vulnerabilities to less important vulnerabilities when the time-to-exploitation of those important vulnerabilities is decreasing dramatically.

Pressed on whether hype is a problem for security teams, Condon replied that it can be. She believes the press in general, and the security press in particular, are a ‘net good’. “But if you’re a researcher on Twitter, and your incentive is to get 2,000 retweets and get hired, that’s a huge incentive to hype it up – and that can put pressure on reporters.” She added that not all security vendors are innocent when their own product can provide mitigation.

Condon believes there are three primary takeaways from the current Rapid7 research. The first is that widespread threats remain high, even though they are down from 66% in 2021 to 56% in 2022’s dataset. “Common payloads dropped during mass exploitation included cryptocurrency miners, web shells, and a variety of botnet malware in addition to an ever more diverse set of ransomware payloads,” says the report.

The second takeaway is the complexity of the ransomware ecosystem and how that affects visibility and statistics. “The vulnerabilities that we could definitively map to ransomware incidents decreased in 2022 by one-third. Why is this happening, when we and many other firms have seen an increase in the overall volume of ransomware incidents?” she asked.

The obvious conclusion is that ransomware groups are leveraging fewer new vulnerabilities than they did in 2021. “That might be part of the equation, but it almost certainly is not the whole story – the diversification of both the ransomware ecosystem as a whole and also the broader cyber underground comes into significant play here,” she added.

The effect is complex. When the number of vulnerabilities used is decreasing and the number of ransomware families is increasing, it means there are more threat actor payloads to track and there are more TPPs to track and attribute. “All of this contributes to likely lower industry visibility, at least in the short term, into ransomware CVE mappings, and lower confidence levels in tracking full attack chains and timelines. Because of the diversification of the ransomware ecosystem and more limited use of new vulnerabilities, we are probably seeing lower competence and visibility into some of these activities.”

All of this is complicated by Condon’s third takeaway: the time-to-exploit for newly disclosed vulnerabilities. “We believe the time between when a vulnerability is known and when it’s exploited is a really critical metric for security practitioners,” she said. “They must not only choose what to prioritize but must also justify what they are prioritizing with often very limited resources all the way up their chains and across their organization.”

Vulnerability Time to Known Exploitation (Source: Rapid7)

Even considering the statistical disturbance of zero-day exploits, the time between disclosure and exploitation has decreased steadily over the past three years. “In 2020, 30% of our report vulnerabilities were exploited in the wild within a week of disclosure. In 2021, that went up to 50%. In 2022, 56% of our reported vulnerabilities were exploited within a week of disclosure.” 

Some of these vulnerabilities may technically be classified as zero-days or n-days. “There were more than half a dozen examples that were not exploited at the time of disclosure but were exploited within a few days,” she added. But zero-day or not zero-day is not a distinction that Rapid7 is trying to make. It concentrates primarily on the time-to-exploitation.

“And the numbers are not good, which is a tough message for a lot of our customers,” she said. This combination of widespread exploitation, reduced visibility into ransomware incidents, and very short time-to-exploitation on new vulnerabilities is simply increasing the pressure on security teams at a time of increasing burnout already brought on by post pandemic stress and unregulated over-working at home.

Related: Chinese Hackers Exploited Fortinet VPN Vulnerability as Zero-Day

Related: VMware Says No Evidence of Zero-Day Exploitation in ESXiArgs Ransomware Attacks

Related: GitHub Updates Policies on Vulnerability Research, ExploitsRelated: Cyber Insights 2023 | Criminal Gangs

https://www.securityweek.com/vulnerabilities-being-exploited-faster-than-ever-analysis/




Vulnerability in Popular Real Estate Theme Exploited to Hack WordPress Websites

A critical vulnerability affecting the Houzez premium WordPress theme has been exploited in the wild, WordPress security company Patchstack warned on Monday.

Houzez is a premium theme for the real estate industry, with more than 35,000 sales on ThemeForest. It allows agencies to easily manage content and listings.

Patchstack CTO Dave Jong discovered recently that the Houzez theme and its associated Houzez Login Register plugin are impacted by a critical vulnerability that can allow an unauthenticated attacker to hack WordPress websites.

Houzez vulnerability exploited

“The theme itself provides registration functionality (must be turned on in the settings) which also allows the user to provide the user role they want to sign up with. Unfortunately, this could be set to administrator to instantly get administrator privileges on the WordPress site,” Jong explained in a blog post.  

The vulnerability is tracked as CVE-2023-26009 in the Houzez plugin and CVE-2023-26540 in the theme. The vendor was informed about the security hole and patched it with the release of versions 2.6.4 (plugin) and 2.7.2 (theme).

Patchstack has been seeing attempts to exploit the vulnerability in the wild, and Jong told SecurityWeek that both the theme and the plugin have been targeted. However, the plugin seems to be targeted more than the theme — it’s unclear why.

According to Jong, an attacker looking to exploit the vulnerability needs to visit the targeted website, grab a nonce token associated with CSRF protection, and then send a maliciously crafted request to the account registration endpoint provided by the Houzez theme or plugin.

Patchstack could not determine what the attackers are hoping to achieve by hacking websites through the Houzez vulnerability because its products block the exploitation attempts.

“However, it is safe to assume that if a site is exploited with this vulnerability and the attacker is logged in with administrator privileges, they are likely to upload a malicious plugin which contains a backdoor,” Jong explained. “This backdoor may perform actions such as listening for commands to be executed on a future date, inject advertisements into the website or redirect traffic to another malicious site.”

The expert added, “These kinds of vulnerabilities tend to be exploited the most as it requires no authentication and it instantly gives the malicious actor access to an account with administrator privileges. Vulnerabilities that require multiple steps or a much higher initial privilege do not tend to be exploited very often as the success rate tends to be lower and it requires much more time and processing power on top of the fact that they don’t tend to give the malicious actor access to write files onto the filesystem of the website.”

WordPress website owners and administrators using the Houzez theme should ensure that their installation is patched to prevent malicious exploitation. 

Related: Critical Vulnerability in Premium Gift Cards WordPress Plugin Exploited in Attacks

Related: Vulnerability in BackupBuddy Plugin Exploited to Hack WordPress Sites

https://www.securityweek.com/vulnerability-in-popular-real-estate-theme-exploited-to-hack-wordpress-websites/




Cisco Patches High-Severity Vulnerabilities in ACI Components

Cisco on Wednesday informed customers about the availability of patches for two high-severity vulnerabilities affecting components of its Application Centric Infrastructure (ACI) software-defined networking solution.

One of these flaws, CVE-2023-20011, impacts the management interface of the Cisco Application Policy Infrastructure Controller (APIC) and Cloud Network Controller. APIC is the unified point of automation and management for ACI.

The vulnerability can be exploited by a remote, unauthenticated attacker to conduct cross-site request forgery (CSRF) attacks by tricking a user into clicking on a malicious link. The attacker could then conduct activities on the targeted system with the privileges of the compromised user.

The second high-severity issue, CVE-2023-20089, affects Cisco Nexus 9000 series Fabric switches in ACI mode, and it can be exploited for denial-of-service (DoS) attacks by an unauthenticated, adjacent attacker. The vendor noted that certain conditions need to be met for exploitation.

Both security holes were discovered internally and there is no evidence of malicious exploitation. 

In addition, Cisco has patched medium-severity flaws in several products, including a UCS Manager and FXOS software issue that exposes backup files, a command injection bug in NX-OS, a command injection in Firepower appliances, and an authentication bypass vulnerability in Nexus extenders (requires physical access). 

The networking giant has also released an informational advisory for a privilege escalation issue related to products running NX-OS software and configured for SSH authentication with an X.509v3 certificate.

Cisco on Wednesday also updated its advisory for CVE-2023-20032, a recently addressed critical vulnerability affecting the ClamAV library. The company has informed customers about the availability of technical information describing CVE-2023-20032, and the existence of a proof-of-concept (PoC) exploit. There is currently no evidence of malicious exploitation. 

Additional information can be found in Cisco’s security advisories. 

Related: Flaw in Cisco Industrial Appliances Allows Malicious Code to Persist Across Reboots

Related: Cisco Patches High-Severity SQL Injection Vulnerability in Unified CM

Related: Cisco Warns of Critical Vulnerability in EoL Small Business Routers

https://www.securityweek.com/cisco-patches-high-severity-vulnerabilities-in-aci-components/




Fortinet FortiNAC Vulnerability Exploited in Wild Days After Release of Patch

In-the-wild exploitation of a Fortinet FortiNAC vulnerability tracked as CVE-2022-39952 was seen just days after a patch was announced, and on the same day a proof-of-concept (PoC) exploit was made public.

Fortinet published 40 security advisories on February 16, including one describing a critical vulnerability in the company’s FortiNAC network access control (NAC) solution. The security hole was discovered internally by Fortinet.

The flaw, an external file name and path control issue, can be exploited by an unauthenticated attacker to write data on a system, which can result in arbitrary code execution. 

On February 21, autonomous pentesting company Horizon3 released a blog post detailing how CVE-2022-39952 can be exploited and also released a PoC exploit. 

On the same day, the nonprofit cybersecurity organization Shadowserver warned that its honeypots had started seeing exploitation attempts coming from multiple IP addresses.

CVE-2022-39952 exploited

On February 22, threat intelligence company GreyNoise also reported seeing broad exploitation of the FortiNAC vulnerability. The firm has so far seen attacks coming from two IPs.

Chile-based cybersecurity firm Cronup also reported seeing mass exploitation on February 22, with attacks coming from 10 IP addresses. While some attempts appear to be designed to identify vulnerable FortiNAC systems, others deploy a reverse shell.

Several Fortinet product vulnerabilities have been exploited in attacks in the past years. The US Cybersecurity and Infrastructure Security Agency (CISA) lists nine such flaws in its known exploited vulnerabilities catalog. 

The most recent is CVE-2022-42475, which has been leveraged by a China-linked threat actor in attacks aimed at government organizations in Europe. 

Related: Fortinet Ships Emergency Patch for Already-Exploited VPN Flaw

Related: High-Severity Command Injection Flaws Found in Fortinet’s FortiTester, FortiADC

Related: Fortinet Confirms Zero-Day Vulnerability Exploited in One Attack

https://www.securityweek.com/fortinet-fortinac-vulnerability-exploited-in-wild-days-after-release-of-patch/




Intel Paid Out Over $4.1 Million via Bug Bounty Program Since 2017

Intel has paid out more than $4.1 million through its bug bounty program since its creation in 2017, according to a product security report published by the chip giant on Wednesday.

Between 2018 and 2021, Intel paid out, on average, $800,000 through its bug bounty program each year for vulnerabilities discovered in the company’s products. In 2022, it awarded $935,000. 

Intel says a total of 243 vulnerabilities were reported in 2022, roughly the same as in the previous three years. More than half of the 2022 vulnerabilities were found internally by the company and 90 security flaws, representing 37% of the total, were reported via its bug bounty program. 

The company engaged 151 researchers last year, more than double compared to the previous three years.

Most of the vulnerabilities were discovered in Intel software, processors, and network communications products. Only two issues were assigned a ‘critical’ severity rating, but 79 were classified as having ‘high’ severity. 

Intel has helped create a hardware common weakness enumeration (CWE) list and 19 of the hardware vulnerabilities addressed last year were assigned to 13 hardware CWEs. 

“To deliver security at scale, we have over 500 dedicated product security staff, perform over 120 hackathons per year, fund 40+ academic research teams, and continue to expand our Bug Bounty programs in innovative ways,” Intel said.

The Intel Product Security Report details several of the company’s cybersecurity initiatives. 

Related: Dozens of Vulnerabilities Patched in Intel Products

Related: Intel Confirms UEFI Source Code Leak as Security Experts Raise Concerns

Related: Intel Patches Severe Vulnerabilities in Firmware, Management Software

https://www.securityweek.com/intel-paid-out-over-4-1-million-via-bug-bounty-program-since-2017/




Google Paid Out $12 Million via Bug Bounty Programs in 2022

Google paid out a total of $12 million through its bug bounty programs in 2022. This includes a $605,000 payout that represents the company’s highest reward ever.

More than 700 researchers from 68 countries were rewarded in 2022 for helping Google make its products and services more secure, roughly the same as in 2021. However, the total bug bounties paid out in 2022 were significantly higher than the $8.7 million paid out the previous year. 

Google said it fixed more than 2,900 issues last year across its products. The $605,000 reward was paid out through the Android Vulnerability Reward Program (VRP), through which the tech giant awarded a total of $4.8 million in 2022. 

It’s unclear what the $600k reward was paid for, but Google has been offering up to $1 million for remote code execution vulnerabilities affecting the Pixel Titan M secure chip. In addition, last year it temporarily offered a maximum of $750,000 for data exfiltration flaws in Titan M.

Of the total amount, $486,000 went to the private Android Chipset Security Reward Program (ACSRP), which is run by Google and Android chipset manufacturers. More than 700 vulnerability reports were submitted through this program. 

As for the Chrome VRP, Google paid out a total of $4 million, including $3.5 million for 360 vulnerabilities in the Chrome browser and $500,000 for 110 bugs in ChromeOS. 

Google has announced that in 2023 it plans on experimenting with the Chrome VRP and informed bounty hunters that it will be offering bonuses.

The company’s Vulnerability Research Grant program continued in 2022, with more than $250,000 in grants awarded to 170 researchers.

Bug bounty hunters rewarded by Google donated more than $230,000 to charities. 

Related: Researcher Says Google Paid $100k Bug Bounty for Smart Speaker Vulnerabilities

Related: Google Launches Bug Bounty Program for Open Source Projects

Related: Google Boosts Bug Bounty Rewards for Linux Kernel Vulnerabilities

https://www.securityweek.com/google-paid-out-12-million-via-bug-bounty-programs-in-2022/