vulns.co
/
GKData.io MCP

Microsoft Corporation · 2 min read

Microsoft Edge Bounty Program

Microsoft Corporation · MSRC. Policy reviewed 2026-10-03. Live terms govern participation.

Open current policy Reviewed policy

Policy and restrictions

Preserve customer data and availability; stop on unauthorized access, report immediately and delete retained data. No social engineering, disruptive automation, unauthorized credential use or post-compromise activity. Confidentiality continues through remediation; attack-enabling details wait another 30 days. Imposed remediation deadlines forfeit eligibility. Safe harbor is conditional.

Eligibility and submission status

Participants must be at least 14; minors need guardian permission. Employer, sanctions and public-sector ethics requirements apply; current/recent Microsoft staff and specified related persons are excluded. New, reproducible findings are required.

The policy invites portal submissions but supplies no explicit open/paused status. A visible policy and program listing do not independently establish availability.

Advertised rewards

The introduction and table advertise USD 250–30,000, while award prose starts at USD 500. The lower table value is retained with that discrepancy. Higher discretionary awards are possible; one submission receives its highest qualifying award, not cumulative program payouts.

Advertised schedules and exceptional ceilings are not individual award evidence.

Published scope snapshot

Captured 2026-10-03. Check the current policy for changes before participating.

In scope · 3 published rows
AssetTypeGroup / eligibility
Microsoft Edge based on ChromiumproductDev, Beta and Stable
WebView2 SDKsoftwarePrerelease and release
WebView2 runtimesoftwareEvergreen, Edge Dev and Beta runtimes
Out of scope · 4 published rows
AssetTypeGroup / eligibility
Internet Explorerproduct
Microsoft Edge based on EdgeHTMLproduct
Microsoft Edge Canary-only buildssoftware
Edge training, documentation, sample and community sitespolicy_category

Review limitations

  • The program revision history ends April 7, 2026; overarching terms are dated September 3, 2026.
  • The Edge page suggests a Standard Award Policy fallback, but that section of the linked Bounty Program Guidelines excludes endpoint/on-premises programs. Fallback eligibility is not assumed.
  • Advertised amounts are not individual award evidence. Authenticated submission availability and payment enrollment were not tested.
  • Public policy review only. Asset inventories and operational instructions are omitted. Live terms prevail; this summary grants no authorization or legal protection.

Sources and provenance

  1. Microsoft Edge Bounty Program and revision history Microsoft · reviewed 2026-10-03
  2. Microsoft Bounty Program Guidelines, terms, safe harbor and Standard Award Policy Microsoft · reviewed 2026-10-03
  3. Microsoft Security Testing Rules of Engagement Microsoft · reviewed 2026-10-03
  4. Microsoft Edge Bounty Program Microsoft Corporation · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software