All domains/properties owned by Ibotta are in scope!
- Ibotta continuously pushes out new code.
- Please take care when testing on production not to compromise the functioning of any Ibotta assets or users on the platform.
Recent Scope Additions
We highly recommend you take a look at this additional attack surface – which hopefully means more vulnerabilities!
|Chrome Extension Beta||Access Here||Here is a User Guide The Ibotta team is looking for testing that ensures the pop-up interaction with their other product areas (such as the next item or loyalty card linking) is secure and would like to know about any sensitive data exposure.|
|Web v2||Access Here||This is a refreshed web application for the Ibotta Team. Please note that there are some scope exclusions for this target: Access Token Exposure, the ability to scrape the site, and data flow to 3rd parties is intended and reports will be considered informational unless they are chained to create a larger vulnerability.|
|$||iOS, Android, API||Web|