Google's Open Source Software Vulnerability Reward Program, known as the OSS VRP, launched in 2022 as a channel for paying outside security researchers who privately report flaws in the open source software Google releases. The scope is broad: it covers projects such as Go, Angular and Protocol Buffers, along with repository settings and supply chain components that sit beneath those codebases. In return for valid, privately disclosed findings, Google pays cash bounties, and for several years the arrangement was held up as a low-cost way to add external security scrutiny on top of the company's own engineering teams.
The economics behind that model depend on a simple bargain. Researchers invest their own time hunting for bugs and are paid only when a report turns out to be real and useful. Google gets a steady stream of outside review it could not staff internally. The numbers show how much the company valued the arrangement. Since launching its first vulnerability reward program in 2010, Google has paid out more than $81.6 million to security researchers. In 2025 alone it awarded a record $17.1 million to more than 700 researchers, a 40 percent increase from the $12 million paid in 2024.
In 2026 that bargain came under strain. A surge of automated submissions, generated with the help of AI tools and invalid in the overwhelming majority of cases, has swamped the engineers and open source maintainers who review incoming reports. On October 1, 2026, Google stopped accepting new product vulnerability reports through the OSS VRP. The program's rules page now carries a blunt notice: "as of October 1, 2026, we are no longer accepting product vulnerabilities submitted to the OSS VRP."
Google did not frame the move as a permanent shutdown. In a post from its official X account, the company said: "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid." The company added that it will "continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027." For now, the door is closed to one category of finding at one of the industry's most prominent bounty programs.
Key Facts
SecurityWeek reported on October 5 that Google temporarily closed the OSS VRP to product vulnerability submissions and that the pause was announced on X on October 1. The scope is narrow in one sense and wide in another. Only product vulnerabilities are covered by the freeze. Supply chain reports are unaffected, and neither are pending reports: Google stated that the change "does not affect product vulnerabilities submitted before October 1, 2026." Reports that arrived before that date are still being processed under the old rules.
Help Net Security reported on October 5 that the program now lists no reward amounts for product vulnerabilities across any of its four project tiers, from OT0 (Flagship) down to OT3 (Low-priority). That detail is a strong signal that the category is not merely paused at the intake form but effectively unwound for the duration, since a bounty program without published payouts for a vulnerability class offers researchers no basis to expect payment. Participants are being redirected to Google's other vulnerability reward programs and to the Patch Rewards Program, which pays for security improvements to the company's open source projects.
One exception remains open. For some Google Cloud repositories that affect Google Cloud products, reports may still be accepted through the Cloud VRP. That carve-out matters because it preserves a route for findings that touch a commercial product line, even as the general open source pipeline is halted.
Tom's Hardware reported on October 4 that Google officially suspended product vulnerability submissions over an influx of invalid AI-driven reports, and that it pointed participants toward alternative programs while it works on the reformatting. TechSpot reported on October 5 that the submissions arriving today are largely slop, containing invalid information and hallucinated vulnerability data, and that Google is making a specific exception for supply chain reports and for reports about particularly dangerous flaws.
The OSS VRP freeze did not arrive in a vacuum. In May 2026, Google changed its Chrome and Android reward programs in response to growing AI use: standard Chrome payouts were reduced, Android began prioritizing harder-to-find vulnerability types, and the top reward for a zero-click Pixel Titan M exploit with persistence rose from $1 million to $1.5 million. In March 2026, the Internet Bug Bounty program run by HackerOne paused new submissions, saying the speed and volume of AI-assisted vulnerability discoveries had outpaced the open source community's ability to deliver fixes. In mid-September 2026, Intel removed all financial rewards for security flaws in its software, firmware, hardware and services reported through its Intigriti bug bounty program.
Analysis
The bigger picture here is that the bottleneck in vulnerability disclosure has moved. For two decades the scarce resource in software security was finding bugs, and the entire economics of bug bounties, from payout tables to reputation systems, was built to reward scarcity of discovery. AI-assisted tooling has attacked that assumption directly by making the generation of plausible-looking reports nearly free. What remains scarce is not the report but the human attention needed to triage it, and Google's decision is a straightforward response to a market where the supply of submissions has outrun the capacity to verify them.
What this really means is that the cost of a bad report has become comparable to the value of a good one, at least at the intake layer. A single invalid submission consumes maintainer time, and a thousand of them can consume a project's entire security review budget for a month. When the vast majority of automated submissions are not valid, as Google's own statement puts it, the rational move for a program operator is to close the front door rather than keep hiring triagers. That is precisely what Google has done, and the reward table's silence on product vulnerabilities shows how completely the calculation shifted.
It is worth noting what Google is not doing. The company has kept its supply chain reporting channel open, has preserved a Cloud VRP path for cloud-affecting repositories, and has pointed researchers toward the Patch Rewards Program. That combination suggests a triage strategy rather than a retreat from external security research: keep the channels where a report maps to a concrete, verifiable impact, and close the one where validation is most expensive relative to payoff. The Q1 2027 commitment adds a deadline to the reformatting, which implies an intent to reopen in some form rather than to end the program quietly.
There is also a reputational dimension that the payout figures make plain. Google has spent more than $81.6 million since 2010 building a relationship with the security research community, and the record $17.1 million paid to more than 700 researchers in 2025 shows how far that relationship has been scaled up. A pause framed as temporary and paired with redirects to other programs is an attempt to protect that relationship. The risk is that researchers who lose a submission channel simply take their findings elsewhere, and rebuilding a pipeline of trusted reporters is slower than shutting one down.
Why It Matters
The freeze at Google is a signal about the whole open source security pipeline. TechSpot's reporting notes that Microsoft Edge, Linux and other major free and open source projects face the same problem, while smaller teams have shut the door on AI-generated contributions to avoid being overwhelmed. When a company with Google's resources concludes that it cannot keep up with intake, projects with a handful of volunteer maintainers have even less room to absorb the load.
The precedents run in one direction. BleepingComputer reported on October 4 that the curl command-line utility and library ended its HackerOne bug bounty program in January 2026 after its maintainer was overwhelmed by AI slop reports, and that Intel later stripped financial rewards from its Intigriti program. Each of those decisions removed a channel that had previously produced real fixes. The cumulative effect is a narrower set of places where a genuine, well-researched finding can be submitted and paid for.
There is a security consequence too. Bug bounties exist partly to route discoveries into private disclosure rather than open exploitation. Cutting off intake does not make the vulnerabilities disappear; it changes where the reports go, and it reduces the incentive for a researcher to invest the weeks of work that a serious finding often requires. For the open source projects Google sponsors, the practical result is less external scrutiny during the pause, not more secure code.
Next Up
The next concrete milestone is the first quarter of 2027, when Google has committed to giving an update on the OSS VRP's future. In the meantime, researchers with product findings are being directed to Google's other VRP programs, to the Cloud VRP for some Google Cloud repositories, and to the Patch Rewards Program. Reports submitted before October 1, 2026 are still being processed, so a backlog of legitimate findings will continue to move through the system even while new intake is closed.
The wider question is whether other program operators follow. The pattern so far, from curl to the Internet Bug Bounty to Intel to Google, is that the response to AI-assisted report volume is to restrict intake rather than to build better automated triage. Whatever Google announces in early 2027 will be read closely by every maintainer and bounty administrator now deciding whether their own submission form is still worth leaving open.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.