Google suspended its open source vulnerability rewards program
Google suspended its open source vulnerability rewards program as of 1 October. According to the company, the reason is an increase in automated reports, the vast majority of which are invalid. It promises further information in the first quarter of 2027.
Google suspended the Open Source Software Vulnerability Rewards Program as of 1 October. The program rewarded researchers for finding vulnerabilities in open source software from the company. It promises further information in the first quarter of 2027; it has not specified a date for the program to resume.
According to Google, automated reports have increased significantly, and the vast majority are invalid. The article links this increase to the use of AI. Citing the website Tom’s Hardware, it states that invalid reports or reports containing hallucinations overwhelmed engineers and open source maintainers. Google recommends that participants consider its other vulnerability rewards programs.
Why it matters
The opportunity for security researchers to earn rewards through this program is being suspended. For teams maintaining the affected software, the event has a different impact: according to the article, validating invalid reports overwhelmed them, and according to Google, the increase in these reports led to the suspension of the program.
Two audiences, two different impacts
What this means
For individuals
If you look for vulnerabilities to earn rewards, this program is suspended, and a date for its resumption has not yet been announced.
For a business
According to the article, invalid automated reports overwhelmed engineers and open source maintainers at Google. This has affected the process of receiving and validating security reports.
Risks and compliance More business impacts →Check the original
Event sources
only one source so far · 1 publisher, 1 independent. We count feeds from the same owner only once.