• Send Us A Tip
  • Calling all Tech Writers
  • Advertise
Wednesday, June 10, 2026
  • Login
TechStory
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
TechStory
No Result
View All Result
Home India News

Microsoft pays $20,000 as bounty reward to 2 Indian Boys

by Balraj
July 1, 2021
in India News, News
Reading Time: 2 mins read
0
microsoft-bug-bounty-programe

Image Source: CERTStation

TwitterWhatsappLinkedin

For identifying vulnerabilities in the Microsoft Edge browser, two Indians, Vansh Devgan from Uttar Pradesh and Shivam Kumar Singh from Jharkhand, along with their Russian friend Ignacio Laurence have won a huge bounty reward. They discovered two “vulnerable code” that involves uXSS (Universal Cross-Site Scripting) in Microsoft’s Translator and which comes pre-installed in the Edge browser. For identifying the security flaws and notifying them to the company, Microsoft has rewarded the duo with $20,000 (to approx. 15 lakh).

You might also like

Rajiv Bajaj Exits Bajaj Finserv Board Amid Group Leadership Restructuring

Meta’s Rapid Reversal Tech Giant Deletes NameTag Face-Recognition App Libraries Under Public Scrutiny

New York Legislative Milestone NY FAIR News Act Mandates Public AI Disclosure for Media Companies

Screenshot of Email
Source: Times of India

Last week, Microsoft patched two bugs in its Chromium-based Edge browser, one of which may allow an attacker to bypass security and remotely inject and execute arbitrary code on any website simply by sending a message. CVE-2021-34506 is a major security flaw with a CVSS rating of 5.4. It has a low level of complexity, and an attacker could carry it out without requiring any specific set of permissions, according to Microsoft, which issued the patches on Thursday. However, an exploit would need user interaction.

Whenever the language translation feature in Microsoft Edge is used, the security vulnerability gets activated. If a user browses any website using Edge Chromium, chooses the language-translation tool, an arbitrary code could be triggered to execute any action, giving access to the attacker. As a result, executing arbitrary code was relatively simple, as it only required enabling the auto-translate in Microsoft Edge. However, Microsft has released the patches as mention earlier, and users are urged to update to version 91.0.864.59 of the browser.

These bounty hunters have shown that the attack might be triggered simply by adding a comment to a YouTube vídeo that is in a language different than English and an XSS payload as a proof-of-concept (POC) exploit.

Similarly, a friend request from a Facebook account containing other language content with the XSS payload was detected to execute the code as soon as the recipient viewed out the user’s profile. Vansh Devgan further explains, “We created a profile on Facebook with name in a different language and XSS payload and sent a friend request to the victim (he is using Microsoft edge) as soon as he checks our profile he got hacked (SCC popup because of auto-translation).”

Images of Vansh Devgan and Shivam Kumar Singh
Vansh Devgan and Shivam Kumar Singh | Source: HackerOne/Instagram

Talking about the two Indians who discovered these vulnerabilities, Shivam is a part-time bug bounty hunter, while Vansh has completed his third year in B.Tech Computer Science from Lovely Professional University and is running CyberXplore Private Limited along with his friend Shivam Kumar Singh.

Tags: Bounty RewardBug Bounty ProgrammeCyberXplore Private LimitedMicrosoftMicrosoft EdgeXSS payload
Tweet55SendShare15
Previous Post

Rumored Apple iPhone 13 prototype reveals redesigned camera looks

Next Post

T-Mobile REVVL V+ 5G to compete OnePlus Nord CE in design & pricing

Balraj

Balraj writes about Startup, Business, Technology related news on Techstory... For Business Enquires related to TechStory; Get in touch on: info@techstory.in...

Recommended For You

Rajiv Bajaj Exits Bajaj Finserv Board Amid Group Leadership Restructuring

by Rounak Majumdar
June 10, 2026
0
Rajiv Bajaj Exits Bajaj Finserv Board Amid Group Leadership Restructuring

Rajiv Bajaj, Managing Director and Chief Executive Officer of Bajaj Auto, is set to step down from the board of Bajaj Finserv as part of a broader restructuring...

Read more

Meta’s Rapid Reversal Tech Giant Deletes NameTag Face-Recognition App Libraries Under Public Scrutiny

by Anochie Esther
June 10, 2026
0
quiet biometric code removal

In a swift and defensive damage-control maneuver, Meta Platforms Inc. has rolled out an emergency software update to purge its servers of highly controversial code. On June 5,...

Read more

New York Legislative Milestone NY FAIR News Act Mandates Public AI Disclosure for Media Companies

by Anochie Esther
June 10, 2026
0
New York FAIR News Act AI disclosure

The balance between artificial intelligence advancement and traditional journalistic integrity is facing strict government intervention. Following months of debate, the New York State Legislature passed a landmark, first-in-the-nation...

Read more
Next Post
T-Mobile REVVL V+ 5G to compete OnePlus Nord CE in design & pricing

T-Mobile REVVL V+ 5G to compete OnePlus Nord CE in design & pricing

Please login to join discussion

Techstory

Tech and Business News from around the world. Follow along for latest in the world of Tech, AI, Crypto, EVs, Business Personalities and more.
reach us at info@techstory.in

Advertise With Us

Reach out at - info@techstory.in

Aviator Game India 2026

BROWSE BY TAG

#Crypto #howto 2024 acquisition AI amazon Apple Artificial Intelligence bitcoin Business China cryptocurrency e-commerce electric vehicles Elon Musk Ethereum facebook funding Gaming Google India Instagram Investment ios iPhone IPO Market Markets Meta Microsoft News OpenAI samsung Social Media SpaceX startup startups tech technology Tesla TikTok trend trending twitter US

© 2025 Techstory.in

No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to

© 2025 Techstory.in

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?