MikhbarMIKHBAR
Automation

Google Narrows Open Source Bug Bounty Amid Invalid Reports

Google has temporarily suspended product vulnerability submissions for its Open Source Software Vulnerability Reward Program following a surge in invalid automated reports.

Google Narrows Open Source Bug Bounty Amid Invalid Reports

Google Pauses Product Vulnerabilities in OSS VRP

Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP) as it deals with a surge in automated submissions. The temporary measure was publicly <a href="https://x.com/googlevrp/status/2105689195180179605">announced</a> on X on October 1, according to details covered by <a href="https://www.securityweek.com/google-narrows-open-source-bug-bounty-amid-wave-of-invalid-automated-reports/">SecurityWeek</a>.

According to the company, the adjustment was triggered because of a significant increase in automated submissions where the vast majority turned out to be invalid. The restrictions apply strictly to product vulnerabilities, meaning other areas of the bug bounty initiative operate differently during the pause.

Scope of the Pause and Exemptions

The interruption is localized exclusively to product vulnerability reports and does not affect the program’s supply chain reports or any pending reviews. Furthermore, an update published on the <a href="https://bughunters.google.com/about/rules/open-source/google-open-source-software-vulnerability-reward-program-rules">program’s page</a> clarifies that the change does not impact product vulnerabilities submitted prior to October 1, 2026.

Certain product vulnerability submissions might still find alternative paths. For instance, Google noted that some Google Cloud repositories impacting Google Cloud products could still have reports covering product vulnerabilities accepted via the Cloud VRP.

Alternative Options for Bug Hunters

As Google works to reform and restructure this specific segment of the OSS VRP, it has committed to providing a formal update in Q1 2027. In the meantime, the company encourages researchers to examine its other vulnerability reward programs to find valid impact and submit findings there.

Additionally, bug hunters and security researchers can pivot toward the Patch Rewards Program, which offers incentives for proactively improving the overall security baseline of open source projects rather than just reporting bugs.

Context and Broader Industry Trends

Originally <a href="https://www.securityweek.com/google-launches-bug-bounty-program-open-source-projects/">Introduced in 2022</a>, the OSS VRP provides monetary rewards to researchers discovering security issues within Google’s open source ecosystem. The current pause follows earlier <a href="https://www.securityweek.com/google-adjusts-bug-bounties-chrome-payouts-drop-as-android-rewards-rise-amid-ai-surge/">changes</a> made to Google's Chrome and Android reward structures in May, which were similarly adjusted in response to the rapid rise of automated and AI-driven vulnerability discovery tools.

The wider bug bounty landscape has felt similar strains from automated submissions. Earlier in March, the Internet Bug Bounty program managed by HackerOne also paused new submissions, pointing out that the speed and sheer volume of AI-assisted discoveries outpaced the capacity of the open source community to issue timely fixes.

Sources

  • SecurityWeekGoogle Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

Continue chronologically

Related entity coverage