Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports
Google paused product-vulnerability submissions to its open-source bug bounty after a surge of invalid automated reports.
Google temporarily closed its Open Source Software Vulnerability Reward Program to new product vulnerability submissions, citing a surge of automated reports that are mostly invalid. The pause, announced on October 1, 2026, does not affect supply-chain reports, pending reports, or submissions made before that date. Some Google Cloud repository issues may still be reported through the Cloud VRP, and researchers can use the Patch Rewards Program. Google said it will update the OSS VRP in Q1 2027, after earlier 2026 changes to Chrome and Android bounties in response to AI-assisted vulnerability discovery.
- OSS VRP product-vulnerability submissions paused on October 1, 2026.
- Supply-chain reports and submissions filed before the pause still stand.
- Some Google Cloud product bugs may still use the Cloud VRP.
- Chrome and Android bounty rules were tightened in May over AI reports.
- Google plans an OSS VRP update in the first quarter of 2027.
Full article394 words · extracted from securityweek.com · click to collapse
Google has temporarily closed its Open Source Software Vulnerability Reward Program (OSS VRP) to product vulnerability submissions, saying a growing number of automated reports, most of them invalid, prompted the move.
The pause was announced on X on October 1.
“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” Google said.
Only product vulnerabilities are covered by the pause. According to Google, it has no impact on the program’s supply chain reports or on any pending reports.
“This change does not affect product vulnerabilities submitted before October 1, 2026,” the company noted in an update on the program’s page.
Some product vulnerability reports may still be eligible elsewhere. “For some Google Cloud repos impacting Google Cloud products we may still accept reports covering product vulnerabilities through the Cloud VRP,” Google said.
Advertisement. Scroll to continue reading.
Google wants bug hunters to look for impact in its other vulnerability reward programs and submit their findings there. Researchers can also turn to its Patch Rewards Program, which offers rewards for proactively improving the security of open source projects.
“We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027,” Google said.
[ Read: Will AI Kill the Bug Bounty Industry? ]
Introduced in 2022, the OSS VRP pays researchers for vulnerabilities found in Google’s open source projects.
The OSS VRP pause follows changes Google made in May to its Chrome and Android reward programs, in response to the growing use of AI tools for vulnerability discovery.
Standard Chrome payouts were reduced, as the company began favoring concise reports that provide concrete proof a bug exists. For Android, Google said it would prioritize vulnerability types that are harder for AI tools to find, and the top reward for a zero-click Pixel Titan M exploit with persistence went from $1 million to $1.5 million.
In March, the Internet Bug Bounty (IBB) program run by HackerOne paused new submissions, saying the speed and volume of AI-assisted vulnerability discoveries had outpaced the open source community’s ability to deliver fixes.
Related: Google Paid Out $17 Million in Bug Bounty Rewards in 2025
Related: Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers
Related: OpenAI Launches Bug Bounty Program for Abuse and Safety Risks