Payout guidelines

These guidelines are to help understand the payout decisions for each focus area and the methodology we apply when awarding bounty payouts. Each guideline provides a maximum payout for a particular bug category and describes what mitigating factors would prompt a deduction from that amount. In general, the more mitigating factors that exist, the lower the bounty will be.

The triage team will apply these guidelines when assessing reports submitted to our program, however as these are only guidelines, it is within the team’s sole discretion to assess the mitigating factors and deduction amounts on a case-by-case basis.

BOUNTY EXAMPLEPAYOUT
TEE runtime attacks - Code execution
up to $300k*
TEE runtime attacks - Privilege escalation
up to $300k*
TEE runtime attacks - Data leaks
up to $150k*
VM escape
up to $300k*
Persistence
up to $10k*
Disclaimer: Attacks against the firmware and hardware are out of scope for the Meta Bug Bounty program, but we will work with you to support disclosures to our suppliers.
BOUNTY EXAMPLEPAYOUT
Remote code execution
up to $300k*
Memory / info disclosure
up to $20k*
Denial of service (DoS)
up to $5k*
BOUNTY EXAMPLEPAYOUT
Account Takeover
up to $130k*
Unauthorized actions (e.g., publishing a post as anyone)
up to $65k*
Private Data Access
up to $25k*
BOUNTY EXAMPLEPAYOUT
Facebook, Instagram, and other Meta account take-overs
up to $130k*
Business & page take-overs
up to $50k*
BOUNTY EXAMPLEPAYOUT
Being able to access private user content
up to $130k*
Being able to access sensitive internal Meta data
up to $30k*
Being able to trigger privileged/dangerous actions and modify sensitive data
up to $20k*
Prompt smuggling
up to $5k*
BOUNTY EXAMPLEPAYOUT
Native bug - remote code execution
up to $45k*
Native bug - memory / info leak
up to $10k*
BOUNTY EXAMPLEPAYOUT
SSRF in production and reading the response
up to $40k*
Blind SSRF in production and not reading the response
up to $30k*
Hitting arbitrary endpoints within a corporate network
up to $10k*
Hit a small number of endpoints within the corporate network
up to $1k*
Bonus - demonstrate full control of HTTP request
up to $5k*
BOUNTY EXAMPLEPAYOUT
Being able to leak multiple PII on behalf of any user (email, phone number, state, age, ZIP code, gender, etc. ) using Ads Audience
up to $30k*
Being able to use audiences outside of shared relationships between businesses
up to $7.5k*
Identifying audience composition across businesses
up to $5k*
Abuse of sensitive expectations of different audiences
up to $5k*
BOUNTY EXAMPLEPAYOUT
Being able to post a media as someone else which can be viewed by followers and friends
up to $65k*
Being able to make comments as another user
up to $10k*
Being able to pin comments as another user
up to $5k*
BOUNTY EXAMPLEPAYOUT
Unrestricted creation/usage of promo codes
up to $20k*
Being able to bypass the Meta Ad credits restrictions
up to $10k*
Identifying audience composition across businesses
up to $5k*
BOUNTY EXAMPLEPAYOUT
Read or modify more information than granted through app permissions
up to $25k*
Infer which apps a given user has logged into with Facebook
up to $5k*
Find the global Facebook ID for a user logging into your app
up to $1k*
BOUNTY EXAMPLEPAYOUT
2-Factor Authentication bypass
up to $20k*
BOUNTY EXAMPLEPAYOUT
Bugs that enable identifying a contact that matches a known user ID
up to $10k*
Bugs that enable identifying a user ID matching a known contact point
up to $7.5k*
Point queries that confirm if user A has a contact point X
up to $5k*
Bugs that enable identifying a contact point such as email or phone number matching a user’s known first and last name
up to $3k*
BOUNTY EXAMPLEPAYOUT
Video edits in the composer are not applied in both the trim duration and mute status and the final shared content is the same as the uploaded video file without any edits.
up to $7.5k*
Video edits in the composer are inaccurate by a few seconds in trimming or audio mutes (i.e., not a full video).
up to $2k*
BOUNTY EXAMPLEPAYOUT
Page admin disclosure
up to $5k*
BOUNTY EXAMPLEPAYOUT
Identification
up to $3k*
Search bar
up to $5k*
Location
up to $1.5k*
Age
up to $1k*
Page role
up to $1.25k*
Less impactful leaks
up to $750*

General Payout FAQs

If you wish to donate your bounty to a recognized charitable organization, please do not click the claim link. Instead, start the donation process by using the "Donate to charity" option from the "More Options" menu. All charity donations will be matched by Meta. Please note that once you start the donation process, you will have 45 calendar days to respond as to which recognized charitable organization you would like us to donate your matched bounty. In the event we do not hear from you, including, for example, requesting follow-up from you due to our inability to donate to a proposed organization, we reserve the right to select a charitable organization on your behalf or rescind the bounty payout altogether, in Meta’s sole discretion.
Bug Bounty payouts that are not claimed within 6 months from the date of the payout message will be automatically revoked and rendered ineligible for claiming. It is the responsibility of the researcher to claim their payout within this timeframe.
If you elected to claim your payout via Bugcrowd, please contact Bugcrowd directly at support@bugcrowd.com if you are having a problem with your payment or have a technical support question about payment processing.
To learn more about the Hacker Plus rewards program and Hacker Plus multiplier bonuses, please visit https://bugbounty.meta.com/hackerplus/.

For detailed information & examples on how the Hacker Plus Bonus Payout is calculated, please see Exhibit A of the detailed terms and conditions at https://bugbounty.meta.com/hackerplus/terms

If you would like to be added to our Leaderboard page, please reply to the bounty award notification message you received with the name and website you would like us to use. To allow us to make your name public on the leaderboard, you will also need to make your researcher profile public via the researcher settings.

Bugcrowd Payout FAQs

Please review this article for Bugcrowd specific FAQs related to payments and taxes.
No, Bugcrowd is only processing bug bounty payments for Meta. If you've never registered with Bugcrowd before, the profile you create to receive payments from Meta will be kept private unless you choose to make it public. If your profile is private, Bugcrowd will only contact you about issues related to Meta's Bug Bounty program.