Policy and restrictions
Protect privacy and availability, use controlled accounts, report accidental data exposure and delete retained data after notification. Allow reasonable remediation time; no extortion or personal exploitation. Safe harbor cannot bind third parties.
Eligibility and submission status
Original actionable reports in supported configurations qualify; a 48-hour duplicate window may split awards. Internal discoveries and a seven-day internal-detection window can preclude payment, with exceptions. Contributors of the buggy code, employees, contractors and other business relationships are excluded. Local payment-age and US sanctions requirements apply.
The September 11, 2026 announcement expressly says the Firefox client program continues normally through Bugzilla despite the separate Web program’s pause.
Advertised rewards
Published base ceilings are USD 3,000, 10,000 and 20,000 by impact. Certain mitigation findings receive a 50% bonus; exceptional moderate-impact reports remain discretionary. Bounds are null because no payout floor or single bonus-inclusive ceiling is stated.
Advertised schedules and exceptional ceilings are not individual award evidence.
Published scope snapshot
Captured 2026-10-03. Check the current policy for changes before participating.
| Asset | Type | Group / eligibility |
|---|---|---|
Firefox desktop | browser | Current release and supported development channels |
Firefox for Android | browser | Current release and supported development channels |
Firefox for iOS | browser | Current release and supported development channels |
| Asset | Type | Group / eligibility |
|---|---|---|
Fennec (older Firefox for Android application) | browser | |
End-of-life Mozilla client products | policy_category |
Review limitations
- The FAQ identifies a February 24, 2026 reward-category change: GPU-process findings no longer receive the highest sandbox-escape category solely for that process compromise.
- The reviewed July 10, 2026 announcement transfers Mozilla VPN client coverage into this program. No asset inventory is reproduced.
- No client-specific change-log URL or overall policy revision date was established. Linked submission terms and Bugzilla etiquette were not exhaustively reviewed.
- No authenticated intake or payment test occurred. This policy summary is distinct from the Web program and grants no authorization.
- Only policy, general eligibility and FAQ sources were refreshed; announcement timestamps remain unchanged.
Sources and provenance
- Mozilla Client Bug Bounty Program Mozilla · reviewed 2026-10-03
- Mozilla Security Bug Bounty general eligibility and safe harbor Mozilla · reviewed 2026-10-03
- Mozilla Bug Bounty Program FAQ Mozilla · reviewed 2026-10-03
- Mozilla public program updates: client continuity and policy changes Mozilla / HackerOne · reviewed 2026-10-03
- Mozilla Client Bug Bounty Program Mozilla · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.