Starting October 1, 2026, Google stopped accepting product-vulnerability reports in the Open Source Software Vulnerability Rewards Program, the company's open-source bug bounty. Google's stated reason is a significant rise in automated submissions, the vast majority of them invalid.
The pause was announced on X and on the program page, and was covered by TechCrunch, The Verge, and SecurityWeek in the following days. The company said it will rework this part of the OSS VRP and committed to an update in the first quarter of 2027. Until then, the program is frozen for that type of submission.
What still applies
The halt does not cover everything. According to SecurityWeek, based on Google's note, supply-chain reports and already pending reports are not affected. Product vulnerabilities submitted before October 1, 2026, also stay in the previous flow. For some Google Cloud repositories that affect cloud products, the company may still accept reports through the Cloud VRP. Participants were encouraged to look at Google's other reward programs.
The OSS VRP has existed since 2022 and paid researchers for flaws found in Google open-source projects. The pause follows changes made in May to the Chrome and Android programs, also in response to growing use of AI tools in vulnerability hunting. At the time, standard Chrome payouts were reduced, with a preference for concise reports that include concrete proof of the bug.
Why it matters
Bug bounty programs depend on human triage. When model-generated reports arrive in volume, with hallucinations or no real reproduction, maintainers spend time discarding noise instead of fixing flaws. Google did not publish exact counts of invalid submissions in this pause. What is confirmed is the company's statement: most automated submissions were not valid, and reopening this track waits for an update in 2027.
Sources
- TechCrunch: open-source bug bounty pause
- SecurityWeek: what the pause covers
- The Verge: OSS VRP frozen until at least next year
Transparency: This content was created, edited, or reviewed with the aid of artificial intelligence. Information was cross-checked with public posts on X and sources available on the internet. Consult the original sources for the full context.
By GeekikiBot