Early access: the directory is still filling out, and every rating here is a reported experience.

Researcher profile

SS
SSP
@SuhasSP_SSP · member since August 2026
Contributor Early member
BugScore
9/100
New

Credibility earned elsewhere: verified platform standing, vendor-confirmed credits and reviewed evidence.

Contribution
9/100

What you’ve added here: reviews written, and how useful others found them.

Awarded CVEs 1

Medium — Inappropriate implementation in Extensions (reported 2025-11-16)

Security release ·Google Chrome
How this BugScore is built
Platform standing 0/40
No verified HackerOne profile is linked, so there is no platform signal to read. This is the most defensible input we have. Link and verify HackerOne to earn it.
HackerOne signal percentile 0/20
HackerOne has not published a signal percentile for your account, so this earns nothing yet.
HackerOne impact percentile 0/12
HackerOne has not published an impact percentile for your account, so this earns nothing yet.
HackerOne reputation 0/8
HackerOne shows no reputation figure for your account yet.
Vendor-confirmed credit 9.4/30
You hold 1 verified vendor credit (1 CVE). Credits count most, with diminishing returns as they add up.
Moderator-verified evidence 0/20
You have no moderator-verified private evidence. Private, NDA’d, or direct-to-vendor work can be verified here without going public.
Verification breadth 0/10
You haven’t verified a platform account yet.
Penalties 0-10
No HackerOne warnings and no upheld disputes count against you.

BugScore weighs signal by how hard it is to fake: HackerOne’s own percentiles, vendor-confirmed credits, and evidence a moderator checked. Writing reviews here does not move it. That is Contribution, below. It is a signal to weigh, not a warranty.

How this Contribution is built
Reviews written 4/40
You’ve written 1 program review.
Helpful votes received 1/25
Other members marked your reviews helpful 1 time.
Programs covered 3/15
You’ve reviewed 1 distinct program.
Balanced reviewing 0/10
Post both positive and critical reviews to show you call it as you see it.
Tenure 1/10
You’ve been a member for 1 month.

Contribution measures citizenship on BugRater: reviews, helpful votes, breadth, and tenure. It is cheap to earn by design, and it is kept deliberately separate from BugScore so activity here can never stand in for demonstrated skill.

No verified platform accounts yet.
Security-release credits
Credited by Google Chrome ×1
CVE-2026-17728 · Medium — Inappropriate implementation in Extensions (reported 2025-11-16) Stable Channel Update for Desktop — 151.0.7922.71/.72 Extensions BR2026-0000-001896 ✓ claimed vendor credited Suhas S P
1
Reviews written
1
Programs reviewed
0
Reports represented
1
Helpful votes
How they review
5.0 avg rating given
1 positive 0 mixed 0 negative
Where they hunt
Direct / email 1

Programs reviewed

1

Reviews

Google Vulnerability Reward Program
The Program with Massive Surface Area, Fair Triage, and Great Scope Alignment
positive

Majorly I participate in Google VRP mostly as a casual and daily user rather than doing dedicated, aggressive bug hunting. Most of the security flaws I have reported came from normal day to day usage of Google products rather than active deep scanning. The sheer size of the target surface means anyone with a security mindset can spot impactful vulnerabilities, while experts still have room to dig into obscure endpoints and under-explored domains. The triage team is technically solid, supportive, and fair when aligning scope, though response times can occasionally slow down due to the recent heavy influxes of AI based low quality submissions from others. Overall, it remains a highly transparent, well-coordinated program that I readily recommend. Experiences vary across sub-categories like Chrome VRP or Android VRP, but the main Google VRP track covering web products, AI, and Cloud is consistently smooth to work with.

via Direct / email 1st reply Within 3 days resubmit yes recommends yes skill Novice
SSP · Aug 6, 2026 · Share ↗ 1 helpful