Follow the latest coverage, related explainers and connected technology stories.
Google has temporarily suspended the intake of product vulnerability reports under the OSS VRP after a large influx of automated reports, saying that most of them were invalid. Supply-chain reports and some reports through other bug bounty programs will continue to be accepted, with the company set to announce program changes in the first quarter of 2027.