Google’s open source bug bounty stops taking product vulnerability reports
TL;DR
- Google’s Open Source Software Vulnerability Reward Program stopped accepting product vulnerabilities on 1 October, its rules page says.
- Google said the pause is due to “a significant rise in automated submissions, the vast majority of which are not valid,” TechCrunch reports.
- Supply chain reports still qualify, product reports sent before 1 October stand, and Google commits to an update in Q1 2027.
Read the full story
Sign in with your email to read AI News. It’s free.