Announcement
Google stops accepting product vulnerability reports in its open-source bug bounty program
TechCrunch reports Google blamed a rise in mostly invalid automated submissions for the October 1 change.
TLDR
TechCrunch reports Google cited a “significant rise” in automated submissions, the vast majority of which Google said were invalid. Google’s program rules say it stopped accepting product vulnerability reports through its open-source bug bounty program on October 1, 2026; supply-chain reports remain eligible. Google says it will provide an update in the first quarter of 2027 and encourages researchers to consider its other reward programs.
Combined views
—
First seen ago
— likes— comments— saves— reposts