Google pauses Open Source VRP product-vulnerability submissions after flood of invalid automated (AI) reports — supply-chain reports still accepted; update promised Q1 2027
Google has temporarily stopped accepting product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP), which covers Google-maintained open-source projects such as Go, Angular, Bazel, Protocol Buffers and Fuchsia. Google says the pause is due to a significant rise in automated submissions, the vast majority of which are not valid. OSS VRP supply-chain reports (for example repository settings, GitHub Actions and access-control issues) and reports already in progress are not affected, and product vulnerabilities submitted before 1 October 2026 are still handled. Researchers can still use the Patch Rewards Program (up to US$15,000 for high-impact fixes) and the Cloud VRP for Google Cloud open-source repositories. Google says it will rework the programme and give an update in Q1 2027. Context from BleepingComputer: the OSS VRP launched in August 2022 with rewards from US$100 to US$31,337; curl ended its HackerOne bounty in January and Intel removed bounty payments in mid-September, both amid low-quality AI-generated reports. Wire: BleepingComputer 5 Oct.
- Product
- Google Open Source Software Vulnerability Reward Program (OSS VRP)
- Versions
- n/a — programme change, no CVE
- Exploited in Australia?
- unknown
- Patch to
- Researchers: send Google OSS product bugs through the Patch Rewards Program or Cloud VRP where eligible, and keep using OSS VRP for supply-chain issues. Teams running their own bounty or disclosure inbox: require a working reproduction before triage and plan for higher volumes of automated reports.
Primary: Google Bug Hunters — Open Source Software VRP rules (pause notice) · Vendor: Google Bug Hunters · BleepingComputer — Google halts open-source bug bounty program amid AI spam surge (5 Oct 2026)
