Skip to content

Update the bug bounty policy - #17331

Open
tomrittervg wants to merge 1 commit into
mozilla:mainfrom
tomrittervg:2026-08-07-bounty-policy-update
Open

Update the bug bounty policy#17331
tomrittervg wants to merge 1 commit into
mozilla:mainfrom
tomrittervg:2026-08-07-bounty-policy-update

Conversation

@tomrittervg

Copy link
Copy Markdown
Contributor

Reviewers: decoder, bholley

@tomrittervg
tomrittervg requested a review from a team as a code owner August 7, 2026 20:39

@dveditz dveditz left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I left a minor suggestion, but looks fine whether you accept that change or not

<li>sec-high rated address bar spoofs</li>
<li><a href="https://wiki.mozilla.org/Security_Severity_Ratings/Client">sec-high rated</a> vulnerabilities in supported configurations that fall within our threat model</li>
<li>Memory corruption in the GPU process</li>
<li>Information disclosure from the parent to a less privileged process (e.g. out-of-bounds memory reads via IPC)</li>

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we want to specify "to a web content process" instead of "less privileged" generally? RCE in a web content process is a given, but it would be a different kind of exploit if someone were able to compromise a non-web sandboxed process. We've seen memory corruption in some (GPU and RDD, for example), but I don't think we've ever seen an example of anyone turning those into an RCE in those processes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants