7 ms·
Let's take a moment to talk about the monetary value of this vulnerability. According to the Chrome release page (https://chromereleases.googleblog.com/2026/09
by david_shaw 1mo ago
Let's take a moment to talk about the monetary value of this vulnerability.
According to the Chrome release page (https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html https://chromereleases.googleblog.com/2026/09/stable-channel...), Google paid a researcher $1000 for ethically reporting this.
The CVE associated with it (CVE-2026-85046) is already being exploited in the wild. If we put our thinking caps on, how much do you think this vulnerability is actually worth? How much do you think an organization like Google would spend on, for example, AI tokens or compute to detect this internally before it was found and exploited in the wild?
Ethical disclosure is a complicated topic, because researchers shouldn't hold bugs for ransom or demand high payment. But at the same time, if someone submits a critical issue like this, it makes sense to pay them what the bug's actually worth. Why should a researcher be effectively penalized for responsibly telling a vendor instead of selling the bug to a "research firm" or three-letter agency?
It's one thing if you're an open source project maintainer just trying to put something out to the community. The math is a lot different if you're Google.
- CookieCrisp 1mo agoWhile I agree 1000 is hilariously low for this, worth is hard to quantify. Do you pay what it could theoretically cost your company? the amount the top bidding bad actor would be willing to pay?
- teravor 1mo agoideally, an auction and the vendor or a government can bid against malicious actors (which can also be a government). hard to set up though.
- 27183 1mo agoit seems unlikely google's lawyers would go for this
- teravor 1mo agowell that's why setting it up is hard, because you would want to do it in a way that what they want doesn't matter.
- aeonik 1mo agoMaybe some code is so important and heavily trafficked it becomes a public works project, and various legs can bid for pieces of the project, line how all infrastructure works.
- eru 1mo agoWhat kind of auction would you like to run? Remember that you can sell the same vulnerability to multiple people: it's software you can copy.
- Barbing 1mo agoMaybe needs a Good-Guy-Buy-It-Now w/instant delivery at a fair price. (OK that’s kind of a threat—you’re running an auction and you have the price the corp has to pay to avoid the auction ending.) $1k is so dumb and the fact we’re discussing auctions is proof (hello, Sundar, what you doing over there?). Guess this will change after the next e.g. nationwide hospital ransomware by a hacker who publicly laments bounty rates, if the news cycle accommodates the story long enough.
- eru 29d ago> Guess this will change after the next e.g. nationwide hospital ransomware by a hacker who publicly laments bounty rates, if the news cycle accommodates the story long enough. Negotiating with terrorists or black mailers is a bad idea.
- Barbing 29d agoAgreed. Paying security researchers fair rates is a good idea though right? Keeps future researchers honest?
- eru 27d agoMaybe. But as soon as they threaten to sell it to the baddies or use it for ransomware themselves, I would cease all communication and negotiation. The legitimate threat the researcher has is to disclose to the general public. (And to disclose the next bug to the general public, if there's no good payment.)
- quotemstr 1mo agoYou let the market decide. Google could purchase the bugs on the same market blackhats do.
- jsw97 1mo agoIn the past I would have thought this would incentivize finding bugs that might never be found. However it is now clear that all bugs that can be found will be found. So this makes a ton of sense.
- eru 1mo ago> In the past I would have thought this would incentivize finding bugs that might never be found. Isn't that a good thing? > However it is now clear that all bugs that can be found will be found. So this makes a ton of sense. If Google can find all the bugs nowadays, presumably with AI, why still pay a bug bounty? At least by this logic, bug bounties make less sense now.
- deleted 1mo ago[deleted]
- tptacek 1mo agoGoogle directly competes with the grey market for vulnerabilities. They are competitive in a bunch of different directions: * They pay for vulnerabilities without reliable exploits (more for vulnerabilities that are demonstrably reliable). * They don't require you to actually build a reliable exploit chain. * They pay up front, not in tranches. * They work with essentially all comers, unlike the grey market, where you're generally subcontracting to sell your first few.
- altairprime 1mo agoThe discount Google is getting on bounties versus internal spend is easy to estimate: # assumed to be $0.5mil USD or greater A := What quantity of salaries-and-benefits and AI-dollars does Google spend on zero-day research? # assumed to be greater than zero B := How many full sandbox RCEs are they *hoping* to discover per year with that budget? # $/RCE budgeted spend C := A ÷ B # $/bounty D := $1000 USD # % discount per bounty relative to in-house spend E := (C - D) / C While we lack the data to be sure, it is reasonable to estimate that they're getting a discount of 90% or better versus internal spend on this bounty payment, if one assumes that they do not have many sandbox RCEs left undiscovered. It's unclear whether that assumption holds, but with only a single researcher at an assumed $0.5mil/year (all-inclusive after pay, stock, and benefits) is enough to support the plausibility of that 90% figure, before accounting at market rates for their internal use of the house AIs. So, the most likely case is that they're greedy and miserly, and hope we don't do the math. However I recognize that there are judgment calls to be made here. Either their internal spending finds hundreds of RCEs per year, or they're significantly discounting bounty payments versus their actual worth, or they're negligent in budgeting for RCE discovery at all, or they assign zero value to the security of the Chromium platform underpinning Edge, Electron, et al. All of these are bad in different ways; one hopes a competent tech reporter actually pursues this line of questioning with them!
- cogman10 1mo ago> or they're negligent in budgeting for RCE discovery at all, or they assign zero value to the security of the Chromium platform underpinning Edge, Electron, et al I generally agree, but a 3rd explanation is they figure that too generous a bounty will flood them with reports of minor issues making major ones harder to see (and costing time and money to verify that could be spent looking for security issues).
- altairprime 1mo agoHaving previously worked near a bounty program, I can confirm that they are regardless flooded with people fishing for bounties, even before AI, no matter how cheap the bounty may be — people will grift anything with the most pathetic skript kiddie attempts possible to try and pad their resume with a hit, and bounties that pay $0 are more valuable than pull requests that pay $0.
- esseph 1mo agoThe problem is they are being flooded with both fake AND real disclosures. Imagine if they tried to pay out $250,000 or more per bug? Would the cost be worth it? Maybe, but shareholders may not be pleased... Unless they viewed it as insurance against it being more financially sound for the finder to sell the exploit on the gray or black market instead...
- rglover 1mo agoThey should just multiply a base rate against the severity level. Say the base rate is ranged so low-severity stuff is $500-1K base but high-severity stuff is $10K base. That would net a researcher ~$88K for this specific bug (8.8 severity).
- vlovich123 1mo agoCVE severity is a terrible way to do this. If you follow the cybersecurity space you should know why.
- rglover 29d agoIt's a simple multiplier number and you can set a cap on it (and payout amounts). Where's the fire?
- vlovich123 29d agoCVEs are handed out like candy for non issues, the severity rating system isn’t a serious evaluation of the actual severity (eg a vulnerable function may not even be compiled in), the scoring is inconsistent and subjective and frequently inflated to make the severity seem worse, and with the AI flood they have a massive backlog of handing out CVEs. Like look at CVEs curl dealt with at one point that were just completely bogus and given huge severity ratings to start with. But honestly if you’re the one proposing a “simple solution” maybe do some research yourself.
- 29d ago
- computably 1mo ago> How much do you think an organization like Google would spend on, for example, AI tokens or compute to detect this internally before it was found and exploited in the wild? On average, probably not that much. What's the amortized cost of all testing, static analysis, and audit / code review, per "prevented potential bug"?
- r_lee 1mo agothis is why again, researchers should just honestly sell these to vuln brokers instead of donating them to trillion dollar companies for nothing. nothing will change until big tech can no longer rip off security researchers
- DANmode 1mo agoBut my “Google paid me” on my resume!
- nullbio 1mo agoThey're not going to stop underpaying security researchers just because security researchers decide to sell them to vuln brokers. Advocating for this is reckless.
- r_lee 29d agothey will if it becomes common knowledge that nobody serious is participating in their bug bounty programs. besides, they have incredibly deep pockets and they can afford to pay 6 figures for bugs like these advocating for this is much more ethical than donating money to Google. I'd rather have that money go my family than a multi trillion dollar company.
- bethekidyouwant 29d agoWho is to say they didn’t already do that?
- r_lee 29d agoyou're not allowed to burn exploits like that if you've signed a deal, and who would risk that for $1k? of course it could be a colleague or someone with access to such tools
- deleted 29d ago[deleted]
- 29d ago
- deleted 1mo ago[deleted]
- deleted 1mo ago[deleted]
- Mtinie 1mo ago> Ethical disclosure is a complicated topic, because researchers shouldn't hold bugs for ransom or demand high payment. Why not? Capitalism requires they maximize their value. These profitable companies lay bare at the altar, so they should understand the requirements of their god.
- paxys 1mo agoThere are plenty of people out there who find vulnerabilities and sell them to the highest bidder. Anyone is welcome to do it, including the researchers and hackers reporting them responsibly. There's no need to try and make a convoluted ethical justification. "I did this bad thing because you didn't pay me enough not to" doesn't work past the 6th grade.
- paulpauper 1mo agoThe CVE associated with it (CVE-2026-85046) is already being exploited in the wild. If we put our thinking caps on, how much do you think this vulnerability is actually worth? How much do you think an organization like Google would spend on, for example, AI tokens or compute to detect this internally before it was found and exploited in the wild? in the darkweb, due to crypto, a lot. there is where the $ is, whether it's stealing crypto directly or phishing developers.
- strictnein 1mo agoIf this would have included a full RCE chain with Sandbox escape Google would have paid significantly more. Having just a Sandbox RCE is neat, I've got some on my laptop currently, but it's just a piece of the puzzle.
- stymaar 29d agoThat sounds like a dumb strategy because if non-evil people sit on individual pieces of the puzzle waiting to solve it in full google loses most of the advantage of having a multi-layer system…
- arjie 1mo agoInteresting question, and how much should a user pay Google to fix the vulnerability? I suppose the smallest unit of currency less than the amount of effort they'd have to put in to mitigate it. A fully market economy of bug fixing here is an interesting idea, certainly, but if I'm being honest I actually don't want to pay Google a thousand dollars to fix security issues. In the limit, what would happen is that I end up with the competitor browser Elgoog Emorhc which fixes security issues for free, and pays very little for them, which is the status quo. In the world where security issues are paid for entirely at market rate, it would also be very important to not use browsers by poor groups because they would be unable to pay for security reports on the market and consequently the browsers would be less secure. Interesting idea, for sure, but I don't think it lands in a place I want to go since I neither desire stochastic payments nor desire that all browsers should be from large corporations.
- tptacek 1mo agoIf the vulnerability is already being exploited in the wild --- as in, it's a vector people already know about and are tracking --- it's possibly not worth much at all. Vulnerability valuations depend heavily on the lifespan of the vulnerability; payments on black market are tranched (explicitly or less explicitly, as with "maintenance payments") based on whether they're patched. Further: a vulnerability is probably not worth that much either, even if it's a hypercapable vulnerability, because the grey market buys full enablement kits, not vulnerability information. People making 6 figures on vulnerabilities are selling fully enabled full chain exploit systems, not just intelligence about a sandbox escape.
- 0xbadcafebee 1mo agoHow much money is lost by consumers/businesses for every hour the vulnerability is exploited in the wild with no patch?
- wilg 1mo agoSeems like it was worth $1000 to the researcher in question.
- dataflow 1mo agoIt sounds insultingly low, yeah. I'm trying to imagine why they would pay so little. The only two reasons I can think of are either (a) they were already aware of it and fixing it, and therefore the report didn't really change much, or (b) it requires an unusual configuration or otherwise rare opportunity to that makes it impractical to exploit most users. Really curious to see what the issue was whenever it gets made public.
- solenoid0937 1mo ago(c) there are so many undiscovered vulnerabilities that it doesn't make sense for them to offer a decent payout
- bawolff 1mo ago> But at the same time, if someone submits a critical issue like this, it makes sense to pay them what the bug's actually worth. I'd point out that part of the reason the grey and black market pays so well is because it is that type of market. You have to pay people extra to look past their morals and a risk premium against potential reputational and legal consequences. That said, the gap is probably not just that.
- s1artibartfast 1mo agoIt seems like by definition it is. Someone could sell it on the black market, sell it to Google, or just move on with their life and not sell it. I don't know what this is worth on the black market, maybe I'd be scammed by even trying to sell it. Maybe I don't want to be a bad person. These are all things that go into the prices
- denistaran 29d ago[dead]
- spacedoutman 1mo ago"because researchers shouldn't hold bugs for ransom or demand high payment" Maybe they should now, not like anyone else cares about ethics anyway.
- Alive-in-2025 1mo agoImagine the consideration for the Trump admin, should we pay this guy a million bucks for this attack that gets us into the command system of Iran, or would that be unethical. Of course they don't consider that at this time.
- martyfunkhouser 1mo agoIf you really explore the concept of worth, Google "engineers" are grossly overpaid, otherwise they would have found this themselves already. How many PMs are making more than bug bounties to fetch coffee and bagels? Their priorities are all out of order.
- fuzzfactor 1mo ago>researchers shouldn't hold bugs for ransom or demand high payment. Hell no, the same level bugs at Google should be enthusiastically paid way more than from an undercapitalized startup, who actually needs the help more so. Should be orders of magnitude difference in relation to scale. >it makes sense to pay them what the bug's actually worth. Honest fair-dealing should come into play at least but there are some players who have struck it so rich they can now take enough pride to pay an additional premium just because they can, and their good human nature almost compels them ethically to do way more than the minimum. Just apparently not at Google. If a company has achieved financial success to a degree that they are no longer worried about complete failure for the foreseeable future, then it's only a matter of generosity vs Scrooge-like behavior. What's missing from their overall business acumen if they can't even afford to project an image of generosity yet? If they're not actively making a serious effort to pay the maximum they can well afford for bugs that are truly serious, there is a technical term for that. Chickenshit.
- deleted 1mo ago[deleted]
- gblargg 1mo agoPeople are free to pool their money and offer higher bounties.
- Issue3299 1mo agoMakes you wonder how many hacks wouldn't have occurred if security researchers (and vulnerability disclosure) was actually rewarded proportional to the possible/potential damage said vulnerability may have otherwise caused. It's insulting how poorly incentivised white hats are, just look at how much North Korea is raking in with their cyber shenanigans - current estimates put it at around $6.75 billion to date (over the past 10 years or so).
- avazhi 1mo ago> Ethical disclosure is a complicated topic, because researchers shouldn't hold bugs for ransom or demand high payment. I mean, why not?
- deleted 1mo ago[deleted]
- socalgal2 1mo agoyou're taking someone's word it's being exploited. It says right at the top of the report > allowed a remote attacker to execute arbitrary code *inside the sandbox* A bug in V8 leads to code execution in Chrome's web page process. It does not lead to execution in general. For that you need other exploits that escape the web page process. Those are not detailed here. This CVE is not a big deal. You're responding the poster's title, not the actual CVE
- roywiggins 1mo ago> I chained this bug with an n-day sandbox escape and flagged the v8CTF. https://serotav.github.io/Writeups/v8/when-sorting-leads-to-confusion/ https://serotav.github.io/Writeups/v8/when-sorting-leads-to-...
- socalgal2 29d agoThen what it was chained to is the real issue, not this one. The entire point of having webpages run in their own process is to prevent bugs like this one from doing worse. If you're claiming this bug is the bug that matters, you're effectively claiming they shouldn't need to run pages in their own process and just trust that there are zero bugs. No major browser does that. Not Firefox, not Safari, and not Chromium. that's why bugs in the webpage process pay out very little. Without a worse 2nd bug, they are less serious. Bugs that let you RCE outside the webpage process pay much higher.
- parineum 29d agoThen just call them both one exploit that allows arbitrary sandbox escape.
- TedDoesntTalk 29d agoSophisticated attacks will always leverage multiple vulnerabilities. That’s why you have to think of any vulnerability holistically, not in isolation.
- magicalist 29d ago
- vasco 1mo agoYou've been on HN for 16 years and still comment the lowest brow possible comment on security vulnerability threads that the bounty isn't big enough. How many times do we need to have a top comment crying about the same thing? If you think its too little, sell the exploits you find for more.
- noduerme 1mo agoWell, the implication (and I'm not saying this is right) is that to Google it's only worth $1k to have this brought to their attention by a white hat, versus finding out by exploitation. Which means that they have zero concern from this incident about reputational damage to themselves or their browser. That's pretty good circumstantial evidence of a monopolistic practice, when you can safely assume that there's effectively no difference to your bottom line if your software is hacked.
- kccqzy 29d agoThat’s exactly right, and applies to more than Google. I can’t think of a single browser vendor that would think a single vulnerability materially causes reputational damage.
- thayne 1mo agoBut google is also a monopsony. There isn't anyone else the researcher can ethically sell it to. They just have to take whatever bounty google decides to pay.
- noduerme 1mo agoI'm just saying it's more evidence that Google should be broken up.
- xnx 29d agoHow would you break up Google that would make browsers more secure?
- ruszki 29d agoGoogle should have been split up into shreds like 2 decades ago. Search wants to have income from ads? Good sell it to anybody who pays the most, just like every single newspaper does. Gmail wants to sell our data, or ad space? Good sell them, and not just reuse them internally. Chrome wants to monetize every single request you do? Go, sell them on the open market. And not this fake, "we're separate companies, but only on paper" way. This should have been done a long time ago. Firefox, and the browser market would be much more healthy. Btw, Microsoft, Apple, Facebook, now even Twitter/SpaceX and all of these should have been forced the same way. And of course not just in this field, but all of them, like oil companies. They can pivot, of course, with some grace period, but that would mean giving up something at the end. And if we are there, we can abolish most of trade secrecy too, which exists only to keep up the status quo while hindering progress.
- klm127 1mo agoI heard, on the podcast Darknet Diaries, that there are auctions for zero days in Argentina. This security researcher could probably have cleared a million dollars for a bug like that if they were unscrupulous. The bug bounty should absolutely be higher.
- babuskov 29d agoWith such low payment, it makes one wonder how many exploits exist which were sold to 3rd parties and are currently used in the wild without Google even knowing about it.
- rectang 29d agoThe potential damage is all to users bound by terms and conditions, who are unlikely to collect damages successfully from a vendor. Structurally, vendors don’t have to care. Therefore, vulnerabilities have little direct financial value to a vendor. It’s natural to feel cognitive dissonance because the value to the vendor is so disproportionate to the potential harm to users, but the incentive structure is what it is. A vulnerability which lets an attacker harm the vendor has much higher direct financial value.
- deleted 29d ago[deleted]
- noja 29d ago> how much do you think this vulnerability is actually worth? How much do you think an organization like Google would spend on, for example, AI tokens or compute to detect this internally before it was found and exploited in the wild? What? That's not how you calculate the value of something at all. The value is not based on the prevention, it's the cost of the cure.
- gosub100 29d ago> researchers shouldn't hold bugs for ransom or demand high payment. why? google removed don't be evil off their charter a long time ago. why shouldn't security researchers also seek to maximize profits?
- nullsanity 29d ago[dead]
- AustinDev 29d agoNo company will ever value your privacy or security more than or equal to how much you value them. This is why you gotta keep an unencrypted bitcoin private key in your password manager. I'll know pretty quickly (within ~ 10 minutes or less) that someone has access to all of my passwords.
- TZubiri 29d ago>Ethical disclosure is a complicated topic, because researchers shouldn't hold bugs for ransom or demand high payment Why not? "Hey, I found a cvss 8.8 bug in chrome that allows arbitrary code execution when loading my http url. For X USD I can send a report along, and for Y USD I can send a commit with the fix." Sounds like a basic contract to me What I do think is ethically dubious is: "Hey I found this bug and I will MAKE IT PUBLIC WITHIN 90 DAYS SO LOOK AT IT" I know it's a convention from 'security researchers', but I think the first approach is more ethical than the latter.
- zx8080 28d agoThis sends 2 clear signals: - for developers: don't report, it's not worth it - for users: Google does not care about security as it doesn't pay for reporting (enough).
- etcetcetcetceta 27d ago[dead]