Google has ceased accepting product-vulnerability reports via its Open Source Software Vulnerability Reward Program (VRP) as of October 1st. This decision follows a significant increase in automated submissions, which the company stated were largely invalid. While supply-chain vulnerability reports continue to be accepted, Google anticipates updating the program in the first quarter of 2027. The company noted that while AI can aid in bug discovery, reproducible evidence is crucial for maintainers to effectively triage such findings. AI
IMPACT AI-assisted vulnerability discovery requires careful validation to avoid overwhelming security programs.
RANK_REASON A company is changing its policy for a specific program, impacting how external researchers report vulnerabilities.
Read on Mastodon — mastodon.social →
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →