search
OSS Vulnerability Reward Program
Trends
- 1Google stops accepting product vulnerabilities in OSS bug bounty●Google no longer accepting product vulnerabilities submitted to the OSS VRP
Google has quietly updated the rules of its Open Source Software Vulnerability Reward Program so that product vulnerabilities are no longer accepted. Security researchers flagging flaws in Google products will need to use separate channels, while the program now focuses on Google's open source projects. The change is drawing criticism from researchers who see it as narrowing the scope of coordinated disclosure.
- 2Google ends OSS bug bounty program after AI-generated fake reports▼Discover why the Google OSS VRP is ending. An overwhelming flood of AI-generated fake vulnerability reports forced Googl
Google is shutting down its OSS Vulnerability Reward Program after being overwhelmed by AI-generated fake vulnerability reports. The flood of low-quality, artificial intelligence-written submissions reportedly made it impossible to manage the bug bounty scheme effectively. Security researchers are debating the episode as a sign that AI is now actively undermining the economics of vulnerability research and coordinated disclosure.
- 3Google Pauses OSS Vulnerability Reward Program Over AI Reports●Google Pauses OSS VRP Vulnerability Search Over AI Reports
Google has paused part of its Open Source Vulnerability Reward Program (OSS VRP), halting vulnerability search activities after a wave of AI-generated reports. The company is said to be dealing with a flood of low-quality or automated findings produced by artificial intelligence tools, prompting a temporary stop while it reassesses how such submissions are handled.