search
OSS Vulnerability Reward Program
Trends
- 1Google stops accepting product vulnerabilities in OSS bug bounty●Google no longer accepting product vulnerabilities submitted to the OSS VRP
Google has quietly updated the rules of its Open Source Software Vulnerability Reward Program so that product vulnerabilities are no longer accepted. Security researchers flagging flaws in Google products will need to use separate channels, while the program now focuses on Google's open source projects. The change is drawing criticism from researchers who see it as narrowing the scope of coordinated disclosure.