October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
CarCodyAdvertise
Service recordThe Garage

Automotive Companies Are Formalizing Vulnerability Disclosure—But Bounties Vary

Automakers are formalizing vulnerability reporting, but Tesla, Volvo Cars and Volkswagen illustrate why a disclosure route does not always mean a paid bug bounty.
Entry876 Date Time5 min MechanicCarCody Team

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Automakers are building clearer ways for security researchers and customers to report vehicle vulnerabilities, but a disclosure program does not necessarily mean a paid bug bounty. Tesla describes a reward-oriented process that uses Bugcrowd as its rewards platform while directing vehicle and product reports to Tesla. Volvo Cars accepts coordinated-disclosure reports but says it offers no reward. Volkswagen describes reporting channels within its cybersecurity-management system. The programs sit alongside rules and engineering standards that address vehicle cybersecurity more broadly.

What an automotive vulnerability disclosure program does

A vulnerability disclosure program gives researchers a defined route to alert a company to a security weakness and a way to coordinate investigation and remediation. It is one part of product security, not a substitute for secure design, monitoring, incident response or fixing vulnerabilities.

Automotive programs matter because connected vehicles combine in-vehicle electronics with software and services. The evidence available from individual manufacturers shows different approaches to intake, researcher conditions and compensation; the label “disclosure program” alone does not tell a researcher whether a report is eligible for payment.

Which automakers have publicly described reporting routes?

The examples below are not a current census of the industry. They show how the published approaches differ, based on Tesla and Volvo Cars’ guidance and Volkswagen’s 2025 annual report.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Automaker Published approach Rewards and researcher conditions
Tesla Tesla asks researchers to send vehicle and product reports directly to the company and uses Bugcrowd as its rewards platform. Tesla describes working with good-faith researchers. Reward-oriented, but no reward amount is established here. Its policy calls for proof-of-concept details, reasonable time for remediation, permission to access the vehicle and avoidance of unsafe conditions. It limits research to specified infotainment, gateway, Tesla-developed ECU and energy-product mechanisms. (Tesla product-security policy)
Volvo Cars Accepts private coordinated-disclosure reports. Volvo Cars says it does not operate a public bug bounty program and offers no reward for submissions. (Volvo Cars vulnerability-reporting guideline)
Volkswagen Group Its 2025 annual report says customers can report potential vulnerabilities through brand channels within the group’s Automotive Cybersecurity Management System. The report does not state a researcher reward model or provide a single group-wide researcher intake route.

The distinction between a reporting channel and a bounty is important: researchers should check each automaker’s current policy for eligible products, authorized methods, submission route, disclosure coordination and any reward terms. A company’s participation in a past event or platform is not, by itself, proof that a program is currently open.

How to report a vehicle vulnerability responsibly

Use the manufacturer’s published security-reporting guidance as the controlling source for the specific vehicle, service or product. If it does not explain whether a test is authorized, ask before proceeding rather than assuming that ordinary access to a vehicle grants permission for security testing.

  1. Find the manufacturer’s current security contact or policy. Check that it covers the affected brand, model, service or product, and note the approved submission route. Some programs use a direct company channel; others may involve a managed platform.
  2. Confirm authorization and scope first. Follow the policy’s ownership, permission and access requirements. Tesla, for example, requires permission to access the vehicle and specifies product mechanisms within its research scope.
  3. Keep testing safe and limited. Do not create unsafe vehicle conditions, disrupt services, or access data or systems beyond what is necessary to demonstrate the issue. Tesla’s policy explicitly asks researchers to avoid unsafe conditions.
  4. Send a reproducible report through the stated route. Include the affected component or service, relevant version or configuration if known, the steps needed to reproduce the issue, and proof-of-concept details requested by the program. Avoid including unrelated personal or vehicle data.
  5. Coordinate disclosure with the company. Give the manufacturer a reasonable opportunity to investigate and address the issue, and follow its policy about public disclosure. Tesla’s policy specifically refers to allowing reasonable remediation time.

These are practical safeguards, not a replacement for each company’s terms. The conditions for one automaker do not automatically authorize testing another manufacturer’s vehicle or systems.

What ISO/SAE 21434 and UNECE R155 require

ISO/SAE 21434 covers cybersecurity engineering across the vehicle lifecycle

ISO describes ISO/SAE 21434:2021 as a standard for cybersecurity risk management across the lifecycle of road-vehicle electrical and electronic systems: concept, development, production, operation, maintenance and decommissioning. It supports compliance with UNECE cybersecurity and software-update rules. It is an engineering standard; it does not, by itself, establish that an automaker runs a public bug bounty or pays external researchers. (ISO, ISO/SAE 21434:2021)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

UNECE Regulation 155 concerns cybersecurity management and type approval

UNECE Regulation 155 drives cybersecurity-management requirements for vehicle type approval. Volkswagen’s 2025 annual report says the regulation’s requirements are embedded in its Automotive Cybersecurity Management System. It describes that system as applying across controlled group companies seeking type approval or operating relevant interfaces, and says customers can report potential vulnerabilities through brand channels. These governance requirements are broader than a researcher-facing disclosure policy: they do not establish a universal public intake route or reward scheme for every automaker.

How widespread are automotive disclosure programs?

There is evidence of established external security research, but the available figures do not establish how many manufacturers have active programs today. A 2020 UNECE working document said that the majority of automotive manufacturers in its context operated bug-bounty programs, citing GM/HackerOne and Tesla’s Pwn2Own participation as examples. That statement is historical, not a 2026 adoption count, and event participation is not the same as a currently open disclosure program.

Horiba MIRA’s 2025 report records 79 unique disclosures and says more than 60% were made by four manufacturers. It also indicates that activity increased noticeably from 2018. The report’s figures point to concentrated disclosure activity, not even adoption across the industry; they do not identify a current, complete list of active OEM programs or their reward terms.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to check before choosing a program

  • Intake route: Is the approved path a company email or form, or a managed platform such as Bugcrowd or HackerOne?
  • Scope: Which vehicle systems, ECUs, infotainment components, backend services or energy products are explicitly covered?
  • Authorization: Must the researcher own or register a vehicle, obtain permission, or receive advance approval?
  • Reward terms: Does the company pay for eligible findings, offer recognition only, or expressly state that it offers no reward?
  • Safety and disclosure conditions: What limits apply to privacy, service disruption, vehicle operation, remediation time and public disclosure?

Because scope, authorization and reward terms differ—and can change—verify them on the relevant manufacturer’s current security page before testing or submitting a finding.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

More from the Garage

  1. Entry001Date09 OCT 26Time3 minWhich Brake Pad Should You Buy From RockAuto or Elsewhere?Section: Blog
  2. Entry002Date09 OCT 26Time5 minThe Pros and Cons of Touchless Car Wash SystemsSection: Blog
  3. Entry003Date09 OCT 26Time3 minCan a Trickle Charger or Battery Tender Properly Charge a Car Battery?Section: Blog

Thanks for visiting Carcody

Carcody.com is a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for sites to earn advertising fees by advertising and linking to amazon.co

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.