The company confirmed that the vast majority of recent reports lacked technical merit, forcing maintainers to divert resources away from genuine security research. By freezing the initiative until the first quarter of 2027, Google aims to overhaul its intake process and mitigate the risks identified by cybersecurity experts who have long warned that AI-generated clutter threatens the integrity of vulnerability disclosure platforms.
While this specific program remains dark, Google continues to operate its other security bounty initiatives. Participants seeking to report legitimate flaws in the company's ecosystem are directed toward these alternative channels for the duration of the hiatus.

Comments (0)
No comments yet. Be the first!