Google OSS VRP has temporarily paused product vulnerability submissions and related rewards after Google reported a significant increase in automated reports that were largely invalid.
The change affects Google’s Open Source Software Vulnerability Rewards Program, which rewards security researchers for finding vulnerabilities in Google-maintained open-source projects.
The pause does not shut down the entire program. Rewards for supply-chain compromises and some other security issues remain available, while researchers may also have alternative reporting routes through Google’s Cloud, AI, and other vulnerability reward programs.
For broader coverage of major software vulnerabilities and vulnerability research, see our CVE and vulnerability exploits security hub.
Key takeaway: Google has temporarily stopped accepting reward-eligible product vulnerability reports through the OSS VRP while it reworks that part of the program. Supply-chain compromise rewards remain available.
What Changed in Google’s OSS VRP?
Google’s Open Source Software Vulnerability Rewards Program was created to encourage security researchers to identify meaningful security flaws in open-source projects maintained by Google.
The program covers projects across several sensitivity tiers and historically rewarded both product vulnerabilities and supply-chain security issues.
Beginning October 1, 2026, Google temporarily paused the product vulnerability portion of the program.
The change means researchers can no longer submit ordinary product vulnerabilities through the OSS VRP for rewards while that part of the program is being reworked.
Google has indicated that the pause is temporary and plans to provide an update on the program in the first quarter of 2027.
Why Did Google Pause Product Vulnerability Reports?
Google said the program experienced a significant increase in automated submissions, with the majority of those reports failing to identify valid security vulnerabilities.
Automated vulnerability discovery can help researchers find real issues, but generated findings still need to be manually validated before they are submitted.
Google had already tightened the OSS VRP rules earlier in 2026 to place greater emphasis on reproducible evidence and demonstrated security impact.
In its earlier official OSS VRP rule update, Google said AI can be useful for finding potential security issues, but researchers must validate its output during their investigation.
The updated requirements were designed to reduce reports that describe theoretical or non-reproducible vulnerabilities while still rewarding high-quality research.
Did Google Say AI Generated the Invalid Reports?
No.
Google referred to a rise in automated submissions, but it did not publicly state that all or most of the invalid reports were generated using AI tools.
That distinction is important because automation can include fuzzers, scanners, custom vulnerability-discovery tools, AI systems, and other research techniques.
Google has separately acknowledged that AI is increasingly being used in security research, but the company continues to emphasize that researchers must verify findings before submitting them.
Important: It would be inaccurate to state that Google paused the program specifically because of AI-generated reports unless Google confirms that connection directly.
Which Vulnerability Reports Are Paused?
The change applies to the product vulnerability category of the OSS VRP.
Product vulnerabilities generally include design or implementation flaws in Google’s open-source software that create meaningful security impact.
Examples can include vulnerabilities such as:
- Memory corruption flaws
- Path traversal vulnerabilities
- Security boundary bypasses
- Other implementation defects affecting confidentiality or integrity
Previously, qualifying product vulnerabilities in higher-tier projects could receive monetary rewards.
Which Google Open-Source Projects Are Relevant?
Google organizes OSS VRP projects into different tiers depending on their security importance.
Higher-priority projects have included widely used open-source technologies such as:
- Go
- Angular
- Flutter
- Bazel
- Protocol Buffers
Because these projects are widely used across the software ecosystem, security vulnerabilities discovered in them can potentially affect applications and infrastructure far beyond Google itself.
Supply-Chain Vulnerability Rewards Remain Active
The temporary pause does not apply to every OSS VRP security category.
Google continues to reward qualifying supply-chain compromises.
Supply-chain issues can include vulnerabilities that allow an attacker to tamper with source code, development infrastructure, build pipelines, or published software packages.
These risks remain a major concern because compromising a trusted software project can potentially affect many downstream users at once.
For a real-world example of how open-source dependencies can become an attack path, see our coverage of the npm supply-chain attack involving the Keyv ecosystem.
Current Supply-Chain Reward Ranges
Google’s OSS VRP continues to list rewards for qualifying supply-chain compromises across its project tiers.
| Project Tier | Supply-Chain Reward Range |
|---|---|
| Flagship | $3,133.70 – $31,337 |
| Important | $1,337 – $13,337 |
| Standard | $500 – $3,133.70 |
Other eligible security issues may also continue to receive rewards depending on the affected project and vulnerability category.
What Happened to Product Vulnerability Rewards?
Before the pause, flagship open-source projects could receive product vulnerability rewards ranging from approximately $500 to $7,500.
Important-tier projects previously listed rewards ranging from approximately $101 to $3,133.70.
Those product vulnerability reward ranges have been removed while Google reworks this part of the OSS VRP.
The change should not be interpreted as Google abandoning open-source security research altogether.
Other vulnerability reward programs and patch-based reward mechanisms remain available.
Where Can Researchers Report Vulnerabilities Now?
Researchers who discover a security issue in Google-maintained open-source software may still have alternative reporting options depending on the affected project and impact.
Google points researchers toward several possibilities.
Google Cloud VRP
Some vulnerabilities in Google-maintained open-source repositories may qualify for the Google Cloud Vulnerability Reward Program if the flaw directly affects a Google Cloud product or service.
Researchers should review the official Google Cloud VRP rules before submitting.
Google AI VRP
Security issues affecting Google’s AI products may fall under the company’s AI Vulnerability Reward Program rather than the OSS VRP.
This distinction is increasingly important as open-source projects become integrated into AI products and agentic systems.
Project-Specific Security Channels
Some Google-maintained open-source projects also maintain their own security-reporting processes.
Researchers should check the project’s security policy before deciding where to submit a vulnerability.
Google Patch Rewards Are Still Available
Google also operates a separate Patch Rewards Program for researchers who proactively improve the security of eligible open-source projects.
Unlike a traditional vulnerability bounty, Patch Rewards focuses on accepted security improvements rather than simply submitting a vulnerability report.
Google currently lists rewards of up to $15,000 for qualifying patches, depending on the project and security improvement.
The official Google Patch Rewards Program explains the eligible projects and requirements.
Google Had Already Tightened OSS VRP Rules
The October pause follows earlier changes Google introduced in March 2026.
Those changes were designed to reduce low-quality and non-reproducible submissions.
Google introduced stronger proof requirements for certain product vulnerability reports, particularly in its highest-priority open-source projects.
For some memory corruption vulnerabilities, researchers were required to provide exact OSS-Fuzz reproduction steps or an accepted patch.
The goal was to make sure submissions represented real, actionable security issues rather than theoretical findings generated without meaningful validation.
Why Automated Bug Reports Are Becoming a Challenge
Modern vulnerability research increasingly uses automation to inspect source code, fuzz applications, analyze dependencies, and identify suspicious patterns.
AI-assisted tools can make this process significantly faster.
However, discovering a suspicious code pattern is not the same as proving that a security vulnerability exists.
An automated system may incorrectly interpret:
- Unreachable code as exploitable
- Expected behavior as a security flaw
- Missing context as attacker-controlled input
- Theoretical issues as practical vulnerabilities
When researchers submit large quantities of unverified findings, security teams must spend time reproducing reports that may ultimately prove invalid.
What Researchers Should Do Before Submitting a Bug
Security researchers using automated or AI-assisted tools should validate findings before reporting them.
A strong vulnerability report should generally include:
- A clear description of the vulnerability
- A realistic attack scenario
- Exact reproduction steps
- A working proof of concept where appropriate
- An explanation of security impact
- The affected project and versions
- Relevant logs, traces, or crash information
Automation can accelerate discovery, but human validation remains important for distinguishing meaningful vulnerabilities from false positives.
Does This Mean Google’s Open Source Bug Bounty Is Ending?
No.
The Google open source bug bounty program has not been completely shut down.
The current change is a temporary pause affecting product vulnerability submissions and their associated rewards.
Supply-chain compromises, selected other security issues, Patch Rewards, and alternative Google VRPs remain available.
Google has also indicated that it intends to provide another update on the product vulnerability portion of the program in the first quarter of 2027.
Frequently Asked Questions
Did Google shut down its OSS bug bounty program?
No. Google temporarily paused the product vulnerability portion of the OSS VRP. Other categories, including qualifying supply-chain compromises, remain eligible.
Why did Google pause product vulnerability reports?
Google said it experienced a significant increase in automated submissions, the vast majority of which were not valid vulnerability reports.
Did Google blame AI-generated bug reports?
No. Google referred to automated submissions but did not publicly confirm that AI tools generated the majority of the invalid reports.
Are supply-chain vulnerabilities still rewarded?
Yes. Qualifying supply-chain compromise reports remain eligible for rewards under the OSS VRP.
How much can supply-chain vulnerabilities earn?
Rewards can reach $31,337 for qualifying supply-chain compromises affecting flagship projects.
Can researchers still report Google Cloud open-source vulnerabilities?
Some vulnerabilities that directly affect Google Cloud products may qualify under the Google Cloud VRP, depending on the affected repository and impact.
Does Google still offer rewards for open-source security patches?
Yes. Google’s separate Patch Rewards Program continues to reward qualifying security improvements accepted by eligible open-source projects.
When will Google reopen product vulnerability submissions?
Google has not announced a specific reopening date. It has indicated that an update is expected in the first quarter of 2027.
Final Takeaway
The temporary Google OSS VRP pause highlights a growing challenge for vulnerability reward programs: automation can accelerate security research, but it can also dramatically increase the volume of unverified reports.
Google is not abandoning its open-source security program. Instead, the company is reworking the product vulnerability portion while continuing to reward supply-chain compromises and support other security research channels.
For researchers, the message is clear: automated and AI-assisted discovery can be useful, but reports still need reproducible evidence, demonstrated impact, and careful human validation.
Stay Updated on Open Source Security
Changes to major bug bounty programs can affect how vulnerabilities are discovered, reported, and fixed across widely used open-source projects.
Follow CyberUpdates365 for verified vulnerability updates, open-source security news, supply-chain threats, patch information, and practical guidance for security researchers and defenders.
Security researcher? Before submitting an automated finding, verify the vulnerability manually and provide enough evidence for maintainers to reproduce its real-world security impact.
Official Sources
Google Open Source Security VRP:
Google Bug Hunters Open Source Security program
Google OSS VRP Rule Changes:
Google’s official 2026 OSS VRP rule update
Google Patch Rewards Program:
Official Google Open Source Security Patch Rewards
Google Cloud VRP Rules:
Official Google Cloud Vulnerability Reward Program rules




