Google stopped accepting product vulnerability reports to its open-source bug bounty on 1 October 2026. The company blames a sharp rise in automated submissions, most of them invalid. It has promised an update in the first quarter of 2027.
Also Read: How Much More Do AI Engineers Actually Make in 2026?
What Google has paused
The programme is the Open Source Software Vulnerability Rewards Program, or OSS VRP. Google launched it in August 2022 to pay researchers who find flaws in its open-source projects.
Also Read: News: Nvidia Nears a
It covers projects such as Go, Angular, Bazel, Protocol Buffers and Fuchsia, with rewards from $100 to $31,337, according to Tech Startups, citing BleepingComputer.
Also Read: News and OpenAI Australia hack
What still works
| Route | Status |
|---|---|
| OSS VRP product vulnerability reports | Paused from 1 October 2026 |
| OSS VRP supply-chain reports | Still open |
| Google Cloud VRP and AI VRP | Open, for flaws tied to those products |
| Patch Rewards Program | Open, for security fixes |
Google is using the pause to redesign how reports are submitted, Infosecurity Magazine reports.
Also Read: ASOS Hack: What Happened ASOS data breach and What Customers Should Do
Why AI reports broke the programme
A bug bounty assumes reports are scarce and take effort to write. AI tools remove that cost. Anyone can generate a plausible-looking report in seconds.
Also Read: Gemini 4 Argon: Google's Model for Cyber Defenders First - News
The reports still have to be read by a person. Each invalid one takes engineer time to disprove. When most submissions are invalid, the queue stops working for genuine researchers too.
Also Read: ChatGPT Visual Ads: OpenAI Tests Image Ads
What it means for open-source maintainers
Smaller projects face the same reports without Google's staff. A few steps reduce the load.
- Require a working reproduction. Ask for exact steps or a proof of concept before you triage.
- Use a report template. Affected version, impact and reproduction as required fields.
- Publish a security policy. Say what is in scope and how to report privately.
- Close unreproducible reports quickly. State the reason once and move on.
- Keep paying attention to real ones. Good researchers are caught in the same queue.
If you maintain a plugin, our series covers the release side: publishing a WordPress plugin with SVN and GitHub Actions and passing WordPress.org review. More engineering guides are in Programming.
