Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Artificial Intelligence

Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP).

Zero-day vulnerability

Google has temporarily closed its Open Source Software Vulnerability Reward Program (OSS VRP) to product vulnerability submissions, saying a growing number of automated reports, most of them invalid, prompted the move.

The pause was announced on X on October 1.

“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” Google said.

Only product vulnerabilities are covered by the pause. According to Google, it has no impact on the program’s supply chain reports or on any pending reports.

“This change does not affect product vulnerabilities submitted before October 1, 2026,” the company noted in an update on the program’s page.

Some product vulnerability reports may still be eligible elsewhere. “For some Google Cloud repos impacting Google Cloud products we may still accept reports covering product vulnerabilities through the Cloud VRP,” Google said.

Advertisement. Scroll to continue reading.

Google wants bug hunters to look for impact in its other vulnerability reward programs and submit their findings there. Researchers can also turn to its Patch Rewards Program, which offers rewards for proactively improving the security of open source projects.

“We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027,” Google said.

[ Read: Will AI Kill the Bug Bounty Industry? ]

Introduced in 2022, the OSS VRP pays researchers for vulnerabilities found in Google’s open source projects.

The OSS VRP pause follows changes Google made in May to its Chrome and Android reward programs, in response to the growing use of AI tools for vulnerability discovery. 

Standard Chrome payouts were reduced, as the company began favoring concise reports that provide concrete proof a bug exists. For Android, Google said it would prioritize vulnerability types that are harder for AI tools to find, and the top reward for a zero-click Pixel Titan M exploit with persistence went from $1 million to $1.5 million.

In March, the Internet Bug Bounty (IBB) program run by HackerOne paused new submissions, saying the speed and volume of AI-assisted vulnerability discoveries had outpaced the open source community’s ability to deliver fixes.

Related: Google Paid Out $17 Million in Bug Bounty Rewards in 2025

Related: Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

Related: OpenAI Launches Bug Bounty Program for Abuse and Safety Risks

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Chip Wentz has been appointed as SVP & CISO at Keurig Dr Pepper Inc.

Lumen Technologies has named Kim Keever as CSO.

Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.