Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports
Summary
Google has temporarily paused accepting new vulnerability reports for its open-source software through its bug bounty program, effective October 1st. This decision was made due to a significant increase in invalid automated reports, which overwhelmed the program. However, reports concerning supply chain compromises and those submitted before the deadline are still being processed.
IFF Assessment
The pause in bug bounty rewards for open-source software by a major vendor like Google could disincentivize security researchers from finding and reporting vulnerabilities in these critical projects, potentially leaving them more exposed to exploitation.
Defender Context
This development highlights a growing challenge for bug bounty programs: the influx of low-quality, automated submissions. Defenders should be aware that vendor focus may shift, potentially leading to fewer public disclosures of open-source vulnerabilities if researchers are less motivated to report them. It also underscores the importance of robust vulnerability management processes within organizations for their own open-source dependencies.