Comment by exdsq
$2000 is an absurdly small bounty here - you should up that
$2000 is an absurdly small bounty here - you should up that
> Honestly this was our first bounty ever awarded and we could have been more thoughtful
That’s corporate speak for “no, we won’t pay the researcher any more money.”
50k or 100k would be far more appropriate given the severity of this issue. But overall, this makes me think there's probably a lot more vulnerabilities in Arc that are undiscovered/unpatched.
Also, there's the whole notion of every URL you visit being sent to Firebase -- were these logged? Awful for a browser.