Google Pauses OSS Bug Bounty Submissions
Google has temporarily stopped accepting product vulnerability reports for its OSS VRP, citing a surge in automated, mostly invalid submissions.
Google has temporarily closed its Open Source Software Vulnerability Reward Program (OSS VRP) to product vulnerability submissions, saying a growing number of automated reports, most of them invalid, prompted the move. The pause was announced on X on October 1.
Why Google Hit Pause
According to the company, the decision stems from a flood of automated submissions that are not valid. "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid," Google said. The company framed the shift as a temporary measure while it works on the program's submission process.
Scope of the Pause
Only product vulnerabilities are covered by the pause. Google said the move has no impact on the program’s supply chain reports or on any pending reports. The company also noted that the change does not affect product vulnerabilities submitted before October 1, 2026. In other words, reports that arrived before that date remain in scope.
Where Reports Can Still Go
Some product vulnerability reports may still be eligible elsewhere. Google pointed to its Cloud VRP for certain Google Cloud repositories: "For some Google Cloud repos impacting Google Cloud products we may still accept reports covering product vulnerabilities through the Cloud VRP." The company wants bug hunters to look for impact in its other vulnerability reward programs and submit their findings there. Researchers can also turn to its Patch Rewards Program, which offers rewards for proactively improving the security of open source projects.
Timeline and Commitment
Google did not give a precise restart date but committed to an update. "We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027," Google said. That places the next formal checkpoint in the first quarter of 2027, leaving the product vulnerability intake closed in the interim.
What the OSS VRP Is
Introduced in 2022, the OSS VRP pays researchers for vulnerabilities found in Google’s open source projects. The program is separate from Google's broader bug bounty efforts, which cover products like Chrome and Android. The pause applies only to product vulnerabilities under the OSS VRP, not to the supply chain reports that fall under the same program umbrella.
Google's Earlier Reward Changes
The OSS VRP pause follows changes Google made in May to its Chrome and Android reward programs, in response to the growing use of AI tools for vulnerability discovery. Standard Chrome payouts were reduced, as the company began favoring concise reports that provide concrete proof a bug exists. For Android, Google said it would prioritize vulnerability types that are harder for AI tools to find, and the top reward for a zero-click Pixel Titan M exploit with persistence went from $1 million to $1.5 million.
Broader Bug Bounty Pressure
Google is not the only organization adjusting to automated reporting. In March, the Internet Bug Bounty (IBB) program run by HackerOne paused new submissions, saying the speed and volume of AI-assisted vulnerability discoveries had outpaced the open source community’s ability to deliver fixes. That earlier pause, like Google's, points to a strain on the review pipeline rather than a change in the underlying value of the reports.
What Researchers Should Do Now
For bug hunters who focus on open source, the practical effect is a redirect. Reports that would have gone to the OSS VRP as product vulnerabilities should be evaluated against Google's other programs. The Cloud VRP may accept some Google Cloud product vulnerability reports. The Patch Rewards Program remains open for proactive security improvements to open source projects. And pending reports, along with supply chain submissions, are unaffected by the pause.
Google has not said when product vulnerability intake will reopen, beyond the Q1 2027 update commitment. Until then, researchers submitting product vulnerabilities to the OSS VRP should expect them to be out of scope, while other channels continue to operate.
Why It Matters
The pause highlights a tension that has been building across bug bounty programs: automated tools can generate reports faster than humans can validate them, and the resulting noise can force program operators to narrow intake. For security teams and researchers, this could mean fewer open doors for reporting open source product vulnerabilities in the near term, and more emphasis on programs that reward concrete, verifiable impact. It also suggests that reward programs may continue to adjust their criteria as AI-assisted discovery becomes more common, a pattern already visible in Google's changes to Chrome and Android payouts and in HackerOne's IBB pause.
Sources
- SecurityWeek Original source
Continue Reading
Exchange Flaw Opens Mailboxes to Insiders
Microsoft pushed out-of-band fixes for CVE-2026-96940, a high-severity Exchange Server authorization flaw rated 8.8.
One CISO or two? The role's scope problem
CISOs are juggling technical work and business strategy, and some question whether one title can hold both.
NetScaler Zero-Day Poses Patching Puzzle
Citrix rushed out emergency updates for a SAML authentication flaw already exploited in attacks, but administrators may need to patch twice.