Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports
Google has temporarily paused product vulnerability submissions to its Open Source Software Vulnerability Reward Program after a surge in automated reports, most of which were invalid. The pause does not affect supply chain reports or pending submissions, and Google plans to provide an update in Q1 2027. #Google #OSSVRP #CloudVRP #PatchRewardsProgram

Keypoints

  • Google paused OSS VRP product vulnerability submissions due to a spike in automated invalid reports.
  • The pause does not affect supply chain reports or any pending reports already submitted.
  • Some Google Cloud product issues may still be reported through Cloud VRP.
  • Google is directing researchers to other vulnerability reward programs and the Patch Rewards Program.
  • Google plans to revisit the OSS VRP and provide an update in Q1 2027.

Read More: https://www.securityweek.com/google-narrows-open-source-bug-bounty-amid-wave-of-invalid-automated-reports/