AIによるバグ報告が爆増したためGoogleがバグ報奨金プログラムを一時停止
Googleが提供するオープンソースソフトウェアを対象としたバグ報奨金プログラムの「Google Open Source Software Vulnerability Reward Program(Google OSS VRP)」が、2026年10月1日以降は製品脆弱(ぜいじゃく)性の報告を受け付けなくなったと報告しています。
📢 PSA for open-source bug hunters
— Google VRP (Google Bug Hunters) (@GoogleVRP) October 1, 2026We are temporarily no longer accepting OSS VRP product vulnerability submissions. This does not impact OSS VRP supply chain reports, or any outstanding reports. As an alternative, we encourage you to find impact across our other VRP programs and submit there instead, or pursue the Patch Rewards Program.
Why is this happening? This pause is due to a significant rise in automated submissions, the vast majority of which are not valid. We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027.
https://t.co/nQEkHVfbHS
KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.
