{"id":"a10ee0cf-8f1a-4b6b-8f47-c4a609f20c16","engagementId":"74751a3f-af2d-4b69-897a-08b10ad71065","data":{"brief":{"id":"62dd5fb6-b296-4938-ae25-8007943b70c1","name":"Motorola Mobility Hardware Engagement","tagline":"Want in? Let’s get started on something different, together.","description":"\u003cp\u003eWelcome to the Motorola Mobility IOT program! As part of the Lenovo family, Motorola Mobility is creating innovative smartphones and accessories designed with the consumer in mind. That’s why we’re looking for the thinkers, innovators and problem solvers who believe in working together to challenge the status quo. If you share our commitment to creativity and a passion for bringing new possibilities to life in mobile technology, we want you to say hello to Moto.\u003c/p\u003e\n\n\u003cp\u003eMotorola has a long history of inventing game-changing technology. As a member of the Motorola team, you’ll help us continue our legacy by collaborating with talented colleagues around the globe to create new products that are not only different, but better. We thrive in an open and supportive culture, working in teams where your contribution has impact. We believe in transparency across all levels of the business, valuing every person’s opinion and encouraging new ways of thinking. Here, we all take accountability for our work, we drive consumer-centric decision-making, and we enable our people to push the line of innovation.\u003c/p\u003e\n\n\u003cp\u003eWant in? Let’s get started on something different, together.\u003c/p\u003e\n\n\u003cp\u003eThis program adheres to the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e for the prioritization/rating of findings. If relevant, the deviations from the VRT should be listed here in a markdown table:\u003c/p\u003e","industryTagId":"6825f068-7447-450e-9134-158ae26e18d4","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Motorola Mobility that is not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Motorola Mobility, you can report it \u003ca href=\"https://bugcrowd.com/lenovoresponsibledisclosure\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e. However, be aware that such reports will be ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSeverity Breakdown\u003c/h2\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eRating\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003cth\u003eReward Range\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eP1\u003c/td\u003e\n\u003ctd\u003eDemonstrate an immediate, reproducible, and severe concern to security, privacy, or business operations. In this category are full-chain exploits which take control of the device remotely, exfiltrate sensitive information (e.g. passwords, audio recordings of phone calls), or bypass critical business safeguards, such as the secure boot chain, subsidy locks, or critical device attestations (e.g. financing). Other exploits may be considered for this category if the report contains an evidence-based claim regarding the extent of impact.\u003c/td\u003e\n\u003ctd\u003eMost rewards for this category will range from \u003cstrong\u003e4,000.00 to 5,000.00 USD\u003c/strong\u003e. However, the upper threshold of the award for this category does not have a strict bound and will be brought to the consideration of an award review committee, which will provide an explanation for the final payout. Supply and licensing of tools or methods used to discover the vulnerability readily applicable to Motorola’s code base and for which no public alternative exists can increase award payouts. Upper bounds are subject to budget constraints, however, we strive to supply researchers with proper and equitable funding for responsible disclosure.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP2\u003c/td\u003e\n\u003ctd\u003eInclude non-immediate or less readily reproducible but demonstrably severe concerns for security, privacy, or business operation. These include, for example, crashes that could be bootstrapped into code execution, sensitive information leaks which require an APK to be installed on the device or some user interaction, and bypasses for high-visibility security protections such as the Thinkshield application platform. Exploits against security platform improvements and security features in this category must not be a known part of the versioning pipeline for the given component, i.e. if a mitigation is already in the development stage but not yet deployed or has been previously reported internally.\u003c/td\u003e\n\u003ctd\u003eRewards for this category range from \u003cstrong\u003e1,337.00 to 2,500.00 USD\u003c/strong\u003e, depending on the visibility and severity of the exploit. For example, an android protection bypass leveraging an infrequently used Motorola system service may have less of a reward than that same bypass for awidely-used component marketed as being for security, as the latter indicates a greater expectation of security to the end-user.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP3\u003c/td\u003e\n\u003ctd\u003eInclude medium severity concerns to security, privacy, or business operation. These include non-trivial theft of some sensitive device information that would normally be protected by an SELinux policy or other mechanism, crashes in critical components or applications that cannot be readily bootstrapped into a more serious vulnerability or are prior to other protections, such as ASLR, ARM BTI, code integrity checks, or other application issuesnin bundled or pre-loaded applications managed by Motorola, such as unprotected broadcast receivers.\u003c/td\u003e\n\u003ctd\u003eRewards for this category range from \u003cstrong\u003e300.00 to 750.00\u003c/strong\u003e USD, with the payout determined by the component affected, data leaked, any user interaction requirements, and other factors which may hinder or amplify the issue’s severity.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP4\u003c/td\u003e\n\u003ctd\u003ePresent a low severity concern for security, privacy, or business operation. These include exploits such as HTML injection from an intent that is rendered to a non-critical page of a Motorola managed APK, cross-site-scripting attacks on non-critical web resources, and other issues that do present some potential concern but are likely not to be exploited in practice when compared to other vulnerabilities or do not need an immediate patch or incident response.\u003c/td\u003e\n\u003ctd\u003eRewards for this category range from \u003cstrong\u003e100.00 to 200.00\u003c/strong\u003e USD if the vulnerability is something Motorola will fix and has not already been added to an internal issue tracker.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP5\u003c/td\u003e\n\u003ctd\u003eIssues that do not pose a security concern\u003c/td\u003e\n\u003ctd\u003eUnrewarded\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003ch3\u003eCredentials / Access\u003c/h3\u003e\n\n\u003cp\u003eCredentials are not needed to access any of the devices within the scope. \u003c/p\u003e\n\n\u003ch3\u003eFocus Areas\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eRoot priviledge\u003c/li\u003e\n\u003cli\u003eUnauthorized access\u003c/li\u003e\n\u003cli\u003eBootloader Crash\u003c/li\u003e\n\u003cli\u003eBootloader Full Chain Bypass\u003c/li\u003e\n\u003cli\u003eSubsidy Lock Bypass\u003c/li\u003e\n\u003cli\u003eDevice Financing Bypass\u003c/li\u003e\n\u003cli\u003eLow-Level 0-Day (e.g. in Modem)\u003c/li\u003e\n\u003cli\u003eRemote Sensitive User Data Breach\u003c/li\u003e\n\u003cli\u003eLocal Sensitive User Data Breach\u003c/li\u003e\n\u003cli\u003eRootkit\u003c/li\u003e\n\u003cli\u003eVisible Application Bypass (e.g. ThinkShield)\u003c/li\u003e\n\u003cli\u003eAPK-Level Threat or Information Leak (e.g. implicit intents, \u003c/li\u003e\n\u003cli\u003eunregistered broadcast receivers, poorly-protected content\u003c/li\u003e\n\u003cli\u003eproviders)\u003c/li\u003e\n\u003cli\u003eNative application exploit, e.g. local web server or\u003c/li\u003e\n\u003cli\u003e system service, crash or leak\u003c/li\u003e\n\u003cli\u003eOther non-technical information leak\u003c/li\u003e\n\u003cli\u003eHardcoded credential or credential leak\u003c/li\u003e\n\u003cli\u003eExploit affecting build systems or code signing\u003c/li\u003e\n\u003cli\u003eExploit affecting DevOps system or internal tools\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eOut-of-Scope\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eAndroid related vulnerabilities\u003c/li\u003e\n\u003cli\u003eThird party applications \u003c/li\u003e\n\u003cli\u003eVulnerabilities not directly related to Motorola. (Google, Android, Qualcom etc.)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eReport Format\u003c/h2\u003e\n\n\u003cp\u003eAll reports should contain:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eA descriptive title\u003c/li\u003e\n\u003cli\u003eA step-by-step guide on replicating the vulnerability\u003c/li\u003e\n\u003cli\u003eA demonstrative proof-of-concept showcasing the vulnerability effectively, swiftly, and clearly, with any relevant reproduction output \u003c/li\u003e\n\u003cli\u003eA precise and detailed account of the issue, including the device name and version\u003c/li\u003e\n\u003cli\u003eA list of the components affected, e.g. APK file names, driver names, and versions\u003c/li\u003e\n\u003cli\u003eA thorough root cause analysis explaining why the issue is happening and identifying the specific source code requiring patching for resolution\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eOptionally, the report can also contain a proof-of-concept script, an artifact of the tool used to find the vulnerability, contact information, and a list of relevant, semicolon separated tags, e.g. “kernel module”.\u003c/p\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"5034fa63-1a9a-4071-a473-38baff4cfbc7","name":"In Scope ","targets":[{"id":"16a066a6-18ad-4315-abd0-acdcb6dfda1f","uri":"","name":"All Motorola Devices running Android 13 and above. ","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"366f1c2a-8db8-4300-a897-4aa94e9025dd","sortOrder":0},"sortOrder":0,"tags":[{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"16a066a6-18ad-4315-abd0-acdcb6dfda1f"},{"id":"4cb84232-a78c-4fc6-b51e-cbe67d4ee5f1","name":"IoT","targetId":"16a066a6-18ad-4315-abd0-acdcb6dfda1f"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"60c60b44-30d9-478f-807c-69b01dc82bd7","p1MaxCents":500000,"p1MinCents":400000,"p2MaxCents":250000,"p2MinCents":133700,"p3MaxCents":75000,"p3MinCents":30000,"p4MaxCents":20000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eTarget information:\u003c/h2\u003e\n\n\u003cp\u003eAll Motorola devices that are running Android 13 and above along with the most recent security patch are within scope of testing. \u003c/p\u003e\n\n\u003ch4\u003eMotorola Product List: \u003ca href=\"https://en-us.support.motorola.com/app/software-security-update/g_id/7112#gs=eyJndWlkZUlEIjo3MTEyLCJxdWVzdGlvbklEIjoxLCJyZXNwb25zZUlEIjo0LCJndWlkZVNlc3Npb24iOiJ2akNEQURFcSIsInNlc3Npb25JRCI6InkyQSp4REVxIn0\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAvailable Here\u003c/a\u003e\u003c/h4\u003e","rewardRangeData":{"1":{"min":4000,"max":5000},"2":{"min":1337,"max":2500},"3":{"min":300,"max":750},"4":{"min":100,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"fcaa9901-f104-44d4-af7a-c4965149d1c5","name":"Out of Scope","targets":[{"id":"28691a56-0cb6-4d82-927e-0d13c6850219","uri":"","name":"Vulnerabilities related to web-app related issues","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"177ab77e-0598-4139-9663-1d01d291862a","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"74751a3f-af2d-4b69-897a-08b10ad71065","code":"motorolamobility-iot","state":"in_progress","endsAt":null,"bountyId":"bf83b805-6e72-4067-b86e-60d9466872a4","startsAt":"2023-10-17T12:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Hardware","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/2cac/a8e4/ad2c10f1/7fb0be31e329dc3ae99299ea753eecd3_motorola-solutions-inc.jpg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2023-10-17T12:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/motorolamobility-iot","changelogs":"/engagements/motorolamobility-iot/changelog","submissions":null,"announcements":"/engagements/motorolamobility-iot/announcements","hallOfFame":"/engagements/motorolamobility-iot/hall_of_fames","crowdstream":"/engagements/motorolamobility-iot/crowdstream"},"announcementsCount":2,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/motorolamobility-iot/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=motorolamobility-iot\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/motorolamobility-iot/engagement_subscribers","engagementChangelogsUrl":"/engagements/motorolamobility-iot/changelog","publishedAt":"2025-04-24T16:07:03.936Z","engagementChangelogUrl":"/engagements/motorolamobility-iot/changelog/a10ee0cf-8f1a-4b6b-8f47-c4a609f20c16","createUserFeedbacksUrl":"/engagements/motorolamobility-iot/feedbacks","engagementCrowdstreamUrl":"/engagements/motorolamobility-iot/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}