search
OSS Vulnerability Reward Program
Trends
- 1Google stops accepting product vulnerabilities in OSS bug bounty●Google no longer accepting product vulnerabilities submitted to the OSS VRP
Google has updated the rules of its Open Source Software Vulnerability Reward Program so that product vulnerabilities are no longer accepted under it. The change was flagged on Hacker News, where security researchers are discussing what it means for people who report flaws in Google's open source projects. Reports of product vulnerabilities will now need to go through a different channel.
- 2Google ends OSS bug bounty program after AI-generated fake reports▼Discover why the Google OSS VRP is ending. An overwhelming flood of AI-generated fake vulnerability reports forced Googl
Google is shutting down its OSS Vulnerability Reward Program after being overwhelmed by AI-generated fake vulnerability reports. The flood of low-quality, artificial intelligence-written submissions reportedly made it impossible to manage the bug bounty scheme effectively. Security researchers are debating the episode as a sign that AI is now actively undermining the economics of vulnerability research and coordinated disclosure.
- 3Google Pauses OSS Vulnerability Reward Program Over AI Reports●Google Pauses OSS VRP Vulnerability Search Over AI Reports
Google has paused part of its Open Source Vulnerability Reward Program (OSS VRP), halting vulnerability search activities after a wave of AI-generated reports. The company is said to be dealing with a flood of low-quality or automated findings produced by artificial intelligence tools, prompting a temporary stop while it reassesses how such submissions are handled.