Google Pauses Open Source Bug Bounty Amid Invalid Automated Reports
Google has temporarily halted product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP) due to an influx of automated, mostly invalid reports. The pause, announced on October 1, 2026, on X, does not affect supply chain reports or pending submissions. Google clarified that vulnerabilities submitted before October 1, 2026, remain eligible for rewards.
The tech giant encouraged researchers to submit findings to other programs, such as the Cloud VRP for Google Cloud product vulnerabilities or the Patch Rewards Program for improving open source security. Google plans to reassess and update the OSS VRP by Q1 2027.
This move follows adjustments Google made earlier in 2026 to its Chrome and Android reward programs, aiming to curb AI-assisted vulnerability discoveries. Chrome payouts were reduced, favoring concise reports with concrete proof, while Android rewards prioritized harder-to-find vulnerabilities. The top reward for a zero-click Pixel Titan M exploit with persistence increased from $1 million to $1.5 million.
The OSS VRP pause mirrors actions taken by other programs, such as the Internet Bug Bounty (IBB) run by HackerOne, which also paused new submissions in March 2026 due to the overwhelming volume of AI-assisted discoveries.