It only a possibility but usually once you have the XSS puzzle piece, getting the data may be as trivial as some JS code
It also requires that the user know the document ID- so they would have to identify a document that they want access to, get the ID of that document, embed the document in a website that they can present to a user that DOES have access to that document (which they would be unable to know from the document itself, because the ACLs are only visible to people with view access), and then get them to click submit feedback.
I'll defer to others with more familiarity with bug bounties about the payout appropriateness, not my area of expertise, but it does seem like this would be a very difficult bug to exploit
In comparison, Apple paid 100k [0] for a full account takeover, using an bug so simple that it is unbelievable that it could have passed a code review and testing.
[0]- https://bhavukjain.com/blog/2020/05/30/zeroday-signin-with-a...
Apple's payout seems rather low to me. If I had a vuln like that and knew they were only paying $100k, I would probably seek to monetize it elsewhere.
$3k is almost insulting for something like this, given Google's scale. $31,337 might be more appropriate to at least avoid insult.
Requiring rare user action and document URL? Sure. Live in your bounty bubble.
> If I had a vuln like that and knew they were only paying $100k, I would probably seek to monetize it elsewhere.
But you don't. The person exploiting it knows how much it is worth.
> $3k is almost insulting for something like this
Not for you to decide. He accepted it, meaning it's not insulting.
Anyway, in the past I found a way to takeover an organization account in Google cloud acquisition and they rewarded me $100, saying their "Panel" decided that, Google's VRP panel sucks, so you're right about that.
You may have some impact on your career and be judged by your peers or perhaps brought to civil court for damages, but if done right it’s totally legal to sell exploits.
It's a pretty odd amount too. I'm curious how they arrive at that number.
Example bounty amounts - $1337, $3133.7, $13337 and $31337
EDIT: yep, looks like I missed all the other comments pointing this out, mobile app didn’t load them for some reason. Leaving the comment anyway.
I vividly remember BBS and IRC handles with variations of 31337 in them in the 80s. I'm sure it goes back even farther.