SecurityWeek

Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports


Google has temporarily closed its Open Source Software Vulnerability Reward Program (OSS VRP) to product vulnerability submissions, saying a growing number of automated reports, most of them invalid, prompted the move.

The pause was announced on X on October 1.

“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” Google said.

Only product vulnerabilities are covered by the pause. According to Google, it has no impact on the program’s supply chain reports or on any pending reports.

“This change does not affect product vulnerabilities submitted before October 1, 2026,” the company noted in an update on the program’s page.

Some product vulnerability reports may still be eligible elsewhere. “For some Google Cloud repos impacting Google Cloud products we may still accept reports covering product vulnerabilities through the Cloud VRP,” Google said.

Advertisement. Scroll to continue reading.

Google wants bug hunters to look for impact in its other vulnerability reward programs and submit their findings there. Researchers can also turn to its Patch Rewards Program, which offers rewards for proactively improving the security of open source projects.

“We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027,” Google said.

[ Read: Will AI Kill the Bug Bounty Industry? ]

Introduced in 2022, the OSS VRP pays researchers for vulnerabilities found in Google’s open source projects.

The OSS VRP pause follows changes Google made in May to its Chrome and Android reward programs, in response to the growing use of AI tools for vulnerability discovery. 

Standard Chrome payouts were reduced, as the company began favoring concise reports that provide concrete proof a bug exists. For Android, Google said it would prioritize vulnerability types that are harder for AI tools to find, and the top reward for a zero-click Pixel Titan M exploit with persistence went from $1 million to $1.5 million.

In March, the Internet Bug Bounty (IBB) program run by HackerOne paused new submissions, saying the speed and volume of AI-assisted vulnerability discoveries had outpaced the open source community’s ability to deliver fixes.

Related: Google Paid Out $17 Million in Bug Bounty Rewards in 2025

Related: Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

Related: OpenAI Launches Bug Bounty Program for Abuse and Safety Risks



Source link