1 story

Safety & Security

Google pauses a bug bounty, flooded by automated reports

Its open-source reward program stopped taking reports of flaws in its code on October 1. Google says most automated submissions were not valid, and promises an update in early 2027.

Google has paused the main part of its Open Source Software Vulnerability Reward Program. Since October 1, it no longer accepts reports of security flaws in the code of its open-source projects. Google blames a sharp rise in automated reports, most of which were not valid.