Google’s open source bug bounty stops taking product vulnerability reports

TL;DR

  • Google’s Open Source Software Vulnerability Reward Program stopped accepting product vulnerabilities on 1 October, its rules page says.
  • Google said the pause is due to “a significant rise in automated submissions, the vast majority of which are not valid,” TechCrunch reports.
  • Supply chain reports still qualify, product reports sent before 1 October stand, and Google commits to an update in Q1 2027.

Read the full story

Sign in with your email to read AI News. It’s free.

Share this story

Explain like I’m 15