vulns.co
/
GKData.io MCP

Bugzilla · 1 min read

Mozilla Client Bug Bounty

Paid Bounty

Open current program Reviewed policy

What this record establishes

Reviewed policy

An individually reviewed public policy is linked to this program page.

Read the reviewed policy profile →

Published asset scope

Snapshot captured 2026-10-03. Scope status: Not Captured.

In scope · 3 published rows
AssetTypeGroup / eligibility
Firefox desktopbrowserCurrent release and supported development channels
Firefox for AndroidbrowserCurrent release and supported development channels
Firefox for iOSbrowserCurrent release and supported development channels
Out of scope · 2 published rows
AssetTypeGroup / eligibility
Fennec (older Firefox for Android application)browser
End-of-life Mozilla client productspolicy_category

Capture limits

  • The FAQ identifies a February 24, 2026 reward-category change: GPU-process findings no longer receive the highest sandbox-escape category solely for that process compromise.
  • The reviewed July 10, 2026 announcement transfers Mozilla VPN client coverage into this program. No asset inventory is reproduced.
  • No client-specific change-log URL or overall policy revision date was established. Linked submission terms and Bugzilla etiquette were not exhaustively reviewed.
  • No authenticated intake or payment test occurred. This policy summary is distinct from the Web program and grants no authorization.
  • Only policy, general eligibility and FAQ sources were refreshed; announcement timestamps remain unchanged.

Live policy and platform eligibility still require review.

Sources and collection identity

  1. Official program page Primary source · reviewed 2026-10-03

Appears in Profile. No identity match is inferred from a shared company name.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software