Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports
Google paused product-vulnerability submissions to its open-source bug bounty after a surge of invalid automated reports.
Google temporarily closed its Open Source Software Vulnerability Reward Program to new product vulnerability submissions, citing a surge of automated reports that are mostly invalid. The pause, announced on October 1, 2026, does not affect supply-chain reports, pending reports, or submissions made before that date. Some Google Cloud repository issues may still be reported through the Cloud VRP, and researchers can use the Patch Rewards Program. Google said it will update the OSS VRP in Q1 2027, after earlier 2026 changes to Chrome and Android bounties in response to AI-assisted vulnerability discovery.