Google Pauses Open-Source Bug Bounty Program Until 2027
Google has temporarily halted its Open Source Vulnerability Rewards Program (OSS VRP) until 2027 due to a surge in automated and invalid AI-related submissions. The decision, announced on October 1, aims to manage the influx of reports that have overwhelmed the program. Google’s OSS VRP, launched in August 2022, rewards researchers for identifying vulnerabilities in the company’s open-source projects, with payouts ranging from $100 to $31,337 depending on the severity and impact of the flaws.
The program covers various open-source projects hosted by Google on platforms like GitHub, as well as configuration settings such as workflows and access controls. However, the recent spike in submissions, primarily from automated sources, has prompted Google to pause the program. The company plans to overhaul the OSS VRP and expects to provide an update in the first quarter of 2027.
During the suspension, reports related to supply-chain vulnerabilities and those already submitted will remain unaffected. Google encourages researchers to submit findings to other programs, such as the Google Cloud Vulnerability Reward Program (Cloud VRP) or the AI Vulnerability Reward Program (AI VRP), or to participate in the Patch Rewards Program instead.