www.securityweek.com 5 Oct 2026, 14:26 UTC

Google Pauses Open Source Bug Bounty After Invalid Report Surge

Google Pauses Open Source Bug Bounty After Invalid Report Surge

GOOGLE has paused product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP) after a surge of automated reports, most of which were invalid. The pause, announced on X on 1 October 2026, applies only to product vulnerabilities and does not affect the OSS VRP’s handling of supply chain reports or any reports already pending.

Google says some product vulnerability reports may still be eligible through other channels, such as the Cloud VRP for certain Google Cloud repos, and researchers can alternatively use the Patch Rewards Program to help improve open source security.

The company plans to refine how the OSS VRP handles submissions and has committed to providing an update in the first quarter of 2027. This move follows prior changes to Google’s Chrome and Android reward schemes (notably a shift to conciser, more verifiable reports for Chrome and a focus on harder-to-find vulnerability types for Android, with top bounties increasing in some cases).

The OSS VRP was launched in 2022 to pay researchers for vulnerabilities in Google’s open source projects, and the current pause is positioned as a temporary reform measure while Google adjusts its vulnerability-discovery workflows amid a broader industry backdrop of AI-assisted reporting.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline