Google Temporarily Halts Open Source Bug Bounty Program Amid Automated Report Surge
Google has temporarily suspended its Open Source Software Vulnerability Reward Program (OSS VRP) for product vulnerability submissions due to an influx of automated, mostly invalid reports. The pause, announced on X on October 1, does not affect pending reports or supply chain submissions. Google clarified that product vulnerabilities reported before October 1, 2026, remain eligible for rewards.
Researchers are encouraged to submit findings to other Google programs, such as the Cloud VRP for Google Cloud product vulnerabilities and the Patch Rewards Program for improving open source project security. Google plans to reassess the OSS VRP and provide an update by Q1 2027.
This move follows earlier adjustments to Google's Chrome and Android reward programs in May, aimed at addressing the rise of AI-assisted vulnerability discoveries. The company reduced standard Chrome payouts and increased rewards for harder-to-find Android exploits, such as a zero-click Pixel Titan M exploit with persistence, raising the top reward from $1 million to $1.5 million.
The OSS VRP pause mirrors a similar decision by the Internet Bug Bounty (IBB) program in March, which temporarily halted new submissions due to the overwhelming volume of AI-assisted vulnerability reports exceeding the community's ability to deliver fixes.