Google halts open-source bug bounty program amid surge in invalid reports
Google has temporarily paused its Open Source Software Vulnerability Reward Program (OSS VRP) due to a surge in invalid automated reports. Effective October 1, researchers can no longer submit security flaws in projects like Go, Angular, and Protocol Buffers for rewards. The pause affects only product vulnerability reports, while supply chain compromises and other security issues remain eligible for rewards.
The decision follows a significant rise in automated submissions, most of which were deemed invalid. Google did not specify whether these submissions were generated using AI tools. The company plans to rework the program and expects to provide an update in the first quarter of 2027.
Under the OSS VRP, product vulnerabilities were categorized into four tiers, with rewards ranging from $500 to $7,500 for flagship projects and $101 to $3,133.7 for important ones. These reward amounts were removed from the program's rules on September 30. Researchers are now directed to other channels, such as the Cloud VRP, Patch Rewards Program, or other reward programs, depending on the nature of the vulnerability.
Google had previously taken steps to filter out low-quality reports, including requiring stronger proof for submissions. The Go project also updated its security policy to discourage unfiltered reports generated by large language models (LLMs).