Google Freezes New Product-Flaw Reports to Review Its Open-Source Bounty Program
Google pauses new OSS VRP product-flaw reports amid automated spam, keeps supply-chain cases open, reviews program until Q1 2027.
Illustrative image generated with AI
Google has temporarily stopped accepting new product-vulnerability submissions through its Open Source Software Vulnerability Rewards Program, or OSS VRP, after what the company describes as a sharp rise in automated and mostly invalid reports.
The restriction does not shut down every part of the program. Google says supply-chain reports, already outstanding cases, and product-vulnerability reports submitted before October 1, 2026 remain unaffected. Researchers also retain access to separate Google programs for security patches and eligible Cloud-related vulnerabilities.
The change was reported by BleepingComputer on October 5, 2026, at 04:27 AM. The article does not specify a time zone or provide a precise date on which Google began the pause.
One OSS VRP submission category is temporarily closed
The affected route is for new product-vulnerability reports submitted through the OSS VRP. Google characterized the measure as temporary and said it is reviewing the program’s operation, with further information expected in Q1 2027.
According to the company’s statements cited in the report, three categories are not affected:
- Supply-chain reports filed through the OSS VRP.
- Reports that were already outstanding when the change took effect.
- Product-vulnerability reports submitted before October 1, 2026.
That distinction matters because the action is narrower than a complete termination of Google’s open-source rewards initiative. Researchers can no longer use this channel for new product-flaw submissions during the pause, but Google says other report types and existing cases will continue to be handled.
The cited report does not quantify how many researchers or pending submissions are affected. It also does not identify specific projects associated with outstanding reports.
Google attributes its decision to increased automated reporting and says most of those submissions are invalid. That explanation is a company claim: the cited material does not include submission statistics or an independent assessment of report quality.
Google’s wording also focuses on automation. Although the decision appears in a broader debate about AI-assisted vulnerability reports, the available account does not establish that every automated submission was created with generative AI—or that AI alone caused the pause.
The program covers major Google open-source projects
Google introduced the OSS VRP in August 2022 to reward responsible reporting of security weaknesses in open-source software it maintains. Named projects within its scope include Golang, Angular, Bazel, Protocol Buffers, and Fuchsia, along with critical third-party dependencies.
Coverage extends beyond conventional flaws in application code. The program also accepts eligible findings involving repository and project configurations, including GitHub Actions, application configurations, and access-control rules.
Rewards under the OSS VRP range from $100 to $31,337. The program was designed to prioritize weaknesses that could have a significant effect on the software supply chain, where one compromised component or development process may affect multiple downstream users.
The present change concerns how researchers submit a particular class of findings. It is not a security advisory for Golang, Angular, Bazel, Protocol Buffers, Fuchsia, or any other named project.
No CVE identifiers, affected software versions, severity scores, exploitation details, or deployed-product mitigations are associated with the announcement. There is therefore no patching action for software operators arising directly from this program change.
Researchers still have two alternative Google channels
Researchers who discover open-source security issues will need to determine whether their work fits one of Google’s remaining submission routes.
The Google Patch Rewards Program continues to accept open-source security fixes. Google says that program can pay up to $15,000 for high-impact fixes. It is an option for researchers who can develop and submit a corrective change rather than only report a product vulnerability through the paused OSS VRP route.
The Cloud VRP remains another potential channel. Google says vulnerabilities in Google Cloud open-source repositories can be reported through that program when the issue affects Cloud products.
These alternatives are not described as universal replacements for every OSS VRP product-vulnerability report. Their eligibility conditions remain relevant: the Patch Rewards Program concerns security fixes, while the Cloud VRP route applies where a vulnerability affects a Cloud product.
Researchers with reports submitted before October 1, 2026, or cases already classified as outstanding, are included among the categories Google says will not be affected. The cited account does not state how submissions made on or after that cutoff but before the unspecified effective date of the pause will be treated.
Automated reporting is creating pressure beyond Google
Google’s review comes amid wider concern about the operational cost of processing low-quality or AI-assisted vulnerability submissions. Automated tools can help researchers inspect more code, but each resulting report still requires assessment, reproduction, severity analysis, and often communication with the submitter.
In January, the maintainer of the curl command-line utility and library ended its HackerOne bug bounty program after receiving a large volume of reports characterized as AI-generated and poor quality.
Intel made a different change in mid-September, removing financial rewards for reports covering security flaws in its software, firmware, hardware, and services through the company’s Intigriti bug bounty program. According to the cited account, Intel had not explained that decision.
In May, Microsoft warned that AI tools could increase both the pace and breadth of vulnerability discovery across the software industry, creating additional operational demands. The same account says Microsoft patched 966 flaws in the previous month, including two actively exploited zero-day vulnerabilities, although it does not give a specific calendar date for that release.
These examples involve different programs and policies. They do not by themselves demonstrate that Google, Intel, curl, and Microsoft encountered the same reporting behavior or adopted changes for identical reasons.
Google’s wider bounty operation remains substantial
The temporary restriction affects one part of a much larger vulnerability-reward operation. Google has paid more than $81.6 million to thousands of researchers since starting its first VRP in 2010.
In 2025, the company awarded a record $17.1 million to more than 700 researchers. That represented a 40% increase from the $12 million paid in 2024.
Those figures cover Google’s broader vulnerability-reward activity rather than only the OSS VRP. They also describe payments and participating researchers, not the number of vulnerabilities, submissions, or affected people.
For now, the practical consequence is limited but immediate: researchers cannot file new product-vulnerability reports through the OSS VRP while the pause remains in place. Supply-chain submissions and previously outstanding reports continue according to Google, while qualifying fixes and Cloud-related findings can be directed to the Patch Rewards Program or Cloud VRP.
Google says it will outline the next changes in Q1 2027. Until then, the company’s stated rationale—an influx of automated, mostly invalid reports—remains unverified by independently published submission data.
Sources
This article is an original reworking based on the sources below.




