Google has announced a temporary pause in its Open Source Software Vulnerability Reward Program (OSS VRP) for product vulnerability submissions. This decision, effective October 1, was prompted by a significant increase in automated reports, the vast majority of which were deemed invalid, as detailed by SecurityWeek. This strategic adjustment aims to reformat and improve the efficiency of the program, with Google committing to an update in Q1 2027.
Google Open Source Software Vulnerability Reward Program Changes
The temporary halt specifically targets product vulnerabilities submitted to the OSS VRP. It does not affect supply chain reports, which remain an active part of the program, nor does it impact any product vulnerability reports submitted prior to October 1, 2026. This distinction is crucial for understanding the scope of the program’s redirection. The primary driver for this pause is the overwhelming volume of automated and often low-quality submissions, which strain review resources and divert attention from genuinely impactful findings.
For bug hunters researching Google Open Source Software Vulnerability Reward Program changes, it is important to note that some product vulnerability reports may still be eligible for submission through other channels. For instance, specific Google Cloud repositories that impact Google Cloud products might still accept reports via the Cloud VRP. Additionally, researchers can continue to engage with Google’s Patch Rewards Program, which incentivizes proactive security improvements in open-source projects.
The Evolving Landscape of Bug Bounty Programs and AI’s Impact
This move by Google is not an isolated incident but rather reflects a broader trend within the cybersecurity community, particularly concerning the impact of automated bug reports on VRPs. The increasing sophistication of AI tools for vulnerability discovery has led to a surge in submissions, many of which lack the necessary context or proof of exploitability. Google previously made similar adjustments in May to its Chrome and Android reward programs in response to the growing use of AI tools.
For Chrome, standard payouts were reduced, with a preference given to concise reports offering concrete proof of a bug. The Android program began prioritizing vulnerability types that are more challenging for AI tools to identify, even increasing the top reward for a zero-click Pixel Titan M exploit with persistence from $1 million to $1.5 million. The Internet Bug Bounty (IBB) program, run by HackerOne, also paused new submissions in March for similar reasons, acknowledging that the speed and volume of AI-assisted discoveries had outpaced the open-source community’s ability to deliver fixes. This trend underscores a critical challenge in maintaining effective bug bounty programs while adapting to new discovery methodologies.
Recommendations for Bug Hunters and Developers
For security researchers, understanding these adjustments is key to successfully contributing to Google’s security efforts. While the OSS VRP for product vulnerabilities is on hold, exploring alternatives for submitting Google product vulnerabilities remains viable:
- Google Cloud VRP: Researchers with findings related to Google Cloud repositories and products should check the Google Cloud VRP for submission eligibility.
- Patch Rewards Program: This program rewards proactive improvements to open-source project security, offering an avenue for contribution beyond direct vulnerability reporting.
- Other Google VRPs: Google encourages bug hunters to look for impact in its other vulnerability reward programs, which remain active.
Developers maintaining open-source projects should be aware of the ongoing challenges faced by vulnerability programs due to automated reporting. Prioritizing clear, reproducible reports and focusing on high-impact vulnerabilities can help streamline the review process for remaining VRPs. This strategic pause allows Google to re-evaluate and enhance its program structure to better manage the influx of submissions and focus on meaningful security contributions.
Related: Google Gemini 3.5 Flash Cyber AI: Advanced Vulnerability Management, LLMs Achieve Novel Cryptanalysis: Implications for Digital Security