SOCBB Bug Bounty Program
Hosted by the Linux Foundation, the Bug Bounty Program pays developers to fix real, user-facing bugs in Chromium.
Pick a bug from our approved lists, submit and earn up to $20,000 per fix.
Hosted by the Linux Foundation, the Bug Bounty Program pays developers to fix real, user-facing bugs in Chromium.
Pick a bug from our approved lists, submit and earn up to $20,000 per fix.
Awards are determined by the SOCBB Steering Committee and scaled to the severity and user impact of the bug. SOCBB has reinvested $500,000 USD to support the program.
Only bugs on one of these three approved hotlists are eligible at this time.
LARGE
High-impact bugs with broad user or developer visibility, on the BugBounty-Large hotlist.
SMALL
Targeted fixes with clear user benefit, on the BugBounty-Small hotlist.
Eligible bugs must be open, unowned issues that are directly visible to web developers or end users, reproducible in a stable Chromium-based browser without special flags.
Your fix must be visible in at least one of the following Chromium-based browsers to qualify:

BROWSER
Google Chrome

BROWSER
Microsoft Edge

BROWSER
Opera

BROWSER
Meta In-App Browser

BROWSER
Android WebView
Not at this time. Only bugs on one of the three approved hotlists (BugBounty-Large, BugBounty-Medium, BugBounty-Small) are eligible. We may open the scope in the future.
There is no per-person limit, but only one award is given per confirmed bug fix regardless of how many people contributed to it.
Any new bugs caused by your fix within the two-week stable period must also be fixed before your submission is eligible. They are not independently eligible for payment.
https://chromium.org/getting-involved is a good place to start. You can also email bugbounty@socbb.org with questions.
The program ends when the total budget is reached, unless extended at the Linux Foundation’s discretion. The program page will reflect current status.