Bug Bounty Program
Join our community of security researchers and help shape the future of reverse engineering tools
Join our community of security researchers and help shape the future of reverse engineering tools
Several OOB reads in type info deserialization
reported by Q1ngH3, afang5472, P1umer
How to apply: send your report to bugbounty@hex-rays.com. The report should include the POC code and a small description of the bug and its impact.
The duration of the bounty program: undetermined. We reserve the right to close the program at any moment.
What will be asked from the reporters: a proper and legal picture identification and bank account information within 30 days of the bug acknowledgement.
Collective entries are allowed. The bounty will be paid to the person designated by the group.
Bugs in Hex-Rays products (IDA and the Decompiler)
Security bugs in Hex-Rays code (not third-party code)
Original and previously unreported vulnerabilities
High or critical impact (RCE, privilege escalation, etc.)
Present in the latest public release
Work on clean, unmodified installation
Triggered without user interaction or during natural workflow
Issues with our website
Bugs during explicit debugging sessions or script execution
Anti-debugging and similar tricks
Simple crashes and denial-of-service bugs
Bugs requiring binary patching or registry editing
Issues in third-party/contributed code
Users with active IDA licenses can join our Beta program to get early access to new features and improvements.
How to Join
Log into the portal and click "Subscribe to the Beta Program" button
Beta access
Receive email invitations to upcoming Beta sessions
Requirements
Active IDA license required for participation
Help us make IDA and the Decompiler more secure by reporting security vulnerabilities and earn cash rewards.
Cash Rewards
Log into the portal and click "Subscribe to the Beta Program" button
Impact Focus
High and critical impact vulnerabilities are eligible
Active Program
Ongoing program with undetermined duration
Do you need advice in selecting the right plan or managing your account?