Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports
Google paused paid product-vulnerability reports for its open-source bug bounty after a surge of invalid automated submissions.
Google stopped accepting paid product-vulnerability reports under its Open Source Software Vulnerability Reward Program effective October 1, 2026, citing a surge of mostly invalid automated submissions. Projects including Go, Angular, Flutter, Bazel, and Protocol Buffers no longer list product-vulnerability rewards, previously up to $7,500 for flagship projects. Supply-chain compromise reports remain rewarded, and reports filed before October 1 are unaffected. Google said it will update the program in the first quarter of 2027 and gave no date for resuming product reports.