Google pauses open-source product bug reports after surge in AI submissions

First reported by BleepingComputer at · Updated · 5 sources

Google stopped accepting product vulnerability reports through its Open Source Software Vulnerability Rewards Program on October 1 after an influx of mostly invalid automated submissions. Reports about supply chain compromises remain eligible, according to The Hacker News, while Neowin reported that researchers were directed to Cloud VRP alternatives.

  • According to Cyber Security News, Google plans a program update in the first quarter of 2027.

Covered by 5 publishers within 25 hours of the first report.

Reporting5

BleepingComputer Google halts open-source bug bounty program amid AI spam surge · Sergiu Gatlan
The Hacker News Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports · info@thehackernews.com (The Hacker News)

Related

Topics Google