Arc browser adds security bulletins and bug bounties

Share via:


Arc creator The Browser Company has officially started a bug bounty program to keep its growing Chromium-based browser’s security in check. The company is also launching a new security bulletin to maintain “transparent and proactive communication” with users and researchers on bug fixes and reports.

These security revisions followed a devastating bug a researcher found and reported to the company that would’ve allowed bad actors to insert arbitrary code into anyone’s browser just by knowing their easily findable user ID.

The problem lived inside the Arc Boosts feature that lets you customize any website with CSS and Javascript. On top of its initial mitigations, the company says it now has disabled Boosts with Javascript by default and added a new global toggle to turn Boosts off completely in Arc version 1.61.2.

The researcher, known as xyz3va, was initially paid a $2,000 bounty for the information. Now, with the new program in place, The Browser Company is upping it to $20,000 retroactively. The vulnerability was patched on August 26th.

With the new program, security researchers can submit reports and get rewards based on the bug’s severity. Low severity findings that are “limited scope” or “hard to exploit” could land up to $500, Medium gets up to $2,500, High up to $10,000, and Critical earns the $20,000 ceiling.

The blog post also outlined new practices to find other vulnerabilities, like development guidelines with additional code reviews, adding security-specific code audits, and hiring new staff for the security engineering team.



Source link

Disclaimer

We strive to uphold the highest ethical standards in all of our reporting and coverage. We StartupNews.fyi want to be transparent with our readers about any potential conflicts of interest that may arise in our work. It’s possible that some of the investors we feature may have connections to other businesses, including competitors or companies we write about. However, we want to assure our readers that this will not have any impact on the integrity or impartiality of our reporting. We are committed to delivering accurate, unbiased news and information to our audience, and we will continue to uphold our ethics and principles in all of our work. Thank you for your trust and support.

Popular

More Like this

Arc browser adds security bulletins and bug bounties


Arc creator The Browser Company has officially started a bug bounty program to keep its growing Chromium-based browser’s security in check. The company is also launching a new security bulletin to maintain “transparent and proactive communication” with users and researchers on bug fixes and reports.

These security revisions followed a devastating bug a researcher found and reported to the company that would’ve allowed bad actors to insert arbitrary code into anyone’s browser just by knowing their easily findable user ID.

The problem lived inside the Arc Boosts feature that lets you customize any website with CSS and Javascript. On top of its initial mitigations, the company says it now has disabled Boosts with Javascript by default and added a new global toggle to turn Boosts off completely in Arc version 1.61.2.

The researcher, known as xyz3va, was initially paid a $2,000 bounty for the information. Now, with the new program in place, The Browser Company is upping it to $20,000 retroactively. The vulnerability was patched on August 26th.

With the new program, security researchers can submit reports and get rewards based on the bug’s severity. Low severity findings that are “limited scope” or “hard to exploit” could land up to $500, Medium gets up to $2,500, High up to $10,000, and Critical earns the $20,000 ceiling.

The blog post also outlined new practices to find other vulnerabilities, like development guidelines with additional code reviews, adding security-specific code audits, and hiring new staff for the security engineering team.



Source link

Disclaimer

We strive to uphold the highest ethical standards in all of our reporting and coverage. We StartupNews.fyi want to be transparent with our readers about any potential conflicts of interest that may arise in our work. It’s possible that some of the investors we feature may have connections to other businesses, including competitors or companies we write about. However, we want to assure our readers that this will not have any impact on the integrity or impartiality of our reporting. We are committed to delivering accurate, unbiased news and information to our audience, and we will continue to uphold our ethics and principles in all of our work. Thank you for your trust and support.

Website Upgradation is going on for any glitch kindly connect at office@startupnews.fyi

More like this

FBI seizes $6M from crypto scammers targeting US citizens

Tether says it aided in the recovery of...

Apple not investing in OpenAI after all, new report...

Apple is no longer planning to invest in...

OpenAI might raise the price of ChatGPT to $44...

ChatGPT could get more expensive to use in...

Popular

Upcoming Events

Startup Information that matters. Get in your inbox Daily!