... which is what vulnerability research teams are supposed to do, of course. Finding bugs in other people's products is, effectively, a donation to those projects. Google pays consultants many tens of thousands of dollars a pop to get the same work done for their own products.