vulns.co
/
GKData.io MCP

Mozilla · 2 min read

Mozilla Client Bug Bounty

Mozilla · Bugzilla. Policy reviewed 2026-10-03. Live terms govern participation.

Open current policy Reviewed policy

Policy and restrictions

Protect privacy and availability, use controlled accounts, report accidental data exposure and delete retained data after notification. Allow reasonable remediation time; no extortion or personal exploitation. Safe harbor cannot bind third parties.

Eligibility and submission status

Original actionable reports in supported configurations qualify; a 48-hour duplicate window may split awards. Internal discoveries and a seven-day internal-detection window can preclude payment, with exceptions. Contributors of the buggy code, employees, contractors and other business relationships are excluded. Local payment-age and US sanctions requirements apply.

The September 11, 2026 announcement expressly says the Firefox client program continues normally through Bugzilla despite the separate Web program’s pause.

Advertised rewards

Published base ceilings are USD 3,000, 10,000 and 20,000 by impact. Certain mitigation findings receive a 50% bonus; exceptional moderate-impact reports remain discretionary. Bounds are null because no payout floor or single bonus-inclusive ceiling is stated.

Advertised schedules and exceptional ceilings are not individual award evidence.

Published scope snapshot

Captured 2026-10-03. Check the current policy for changes before participating.

In scope · 3 published rows
AssetTypeGroup / eligibility
Firefox desktopbrowserCurrent release and supported development channels
Firefox for AndroidbrowserCurrent release and supported development channels
Firefox for iOSbrowserCurrent release and supported development channels
Out of scope · 2 published rows
AssetTypeGroup / eligibility
Fennec (older Firefox for Android application)browser
End-of-life Mozilla client productspolicy_category

Review limitations

  • The FAQ identifies a February 24, 2026 reward-category change: GPU-process findings no longer receive the highest sandbox-escape category solely for that process compromise.
  • The reviewed July 10, 2026 announcement transfers Mozilla VPN client coverage into this program. No asset inventory is reproduced.
  • No client-specific change-log URL or overall policy revision date was established. Linked submission terms and Bugzilla etiquette were not exhaustively reviewed.
  • No authenticated intake or payment test occurred. This policy summary is distinct from the Web program and grants no authorization.
  • Only policy, general eligibility and FAQ sources were refreshed; announcement timestamps remain unchanged.

Sources and provenance

  1. Mozilla Client Bug Bounty Program Mozilla · reviewed 2026-10-03
  2. Mozilla Security Bug Bounty general eligibility and safe harbor Mozilla · reviewed 2026-10-03
  3. Mozilla Bug Bounty Program FAQ Mozilla · reviewed 2026-10-03
  4. Mozilla public program updates: client continuity and policy changes Mozilla / HackerOne · reviewed 2026-10-03
  5. Mozilla Client Bug Bounty Program Mozilla · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software