generated: '2026-06-20' method: searched probe: true source: https://www.google.com/.well-known/security.txt notes: >- Android is a Google product; vulnerability disclosure runs through Google's organization-wide program (Google Vulnerability Reward Program / Bug Hunters). Values captured verbatim from Google's RFC 9116 security.txt. policy: - https://g.co/vrp contact: - https://g.co/vulnz - mailto:security@google.com acknowledgments: - https://bughunters.google.com/ encryption: - https://services.google.com/corporate/publickey.txt expires: '2030-04-01T00:00:00z' bug_bounty: program: Google Vulnerability Reward Program (Bug Hunters) url: https://bughunters.google.com/ android_specific: https://bughunters.google.com/about/rules/android-friends evidence: - { source: well-known/android-security.txt, kind: security.txt } - { source: https://www.google.com/.well-known/security.txt, kind: live-fetch, status: 200 }