Google suspends vulnerability search program over automated submissions — TechCrunch
Google has suspended its rewards program for finding vulnerabilities in the company’s open-source software since October 1. The company cited a significant increase in the number of automated submissions, most of which are invalid.
Update in 2027
This concerns the Open Source Software Vulnerability Rewards Program, under which security researchers received rewards for reporting vulnerabilities in Google’s open-source software. In posts on X and on the program’s website, the company announced the pause and promised to provide an update on its further operation in the first quarter of 2027.
More current news is available on the UA.News Telegram channel Telegram.
Invalid and false reports
As TechCrunch reports, citing Tom’s Hardware, Google engineers and maintainers of open-source projects were overwhelmed by reports that could not be confirmed or contained claims fabricated by artificial intelligence. During the pause, participants were encouraged to pay attention to other Google vulnerability reward programs.