Artificial Intelligence

Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP).

Zero-day vulnerability

Google has temporarily closed its Open Source Software Vulnerability Reward Program (OSS VRP) to product vulnerability submissions, saying a growing number of automated reports, most of them invalid, prompted the move.

The pause was announced on X on October 1.

“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” Google said.

Only product vulnerabilities are covered by the pause. According to Google, it has no impact on the program’s supply chain reports or on any pending reports.

“This change does not affect product vulnerabilities submitted before October 1, 2026,” the company noted in an update on the program’s page.

Some product vulnerability reports may still be eligible elsewhere. “For some Google Cloud repos impacting Google Cloud products we may still accept reports covering product vulnerabilities through the Cloud VRP,” Google said.

Advertisement. Scroll to continue reading.

Google wants bug hunters to look for impact in its other vulnerability reward programs and submit their findings there. Researchers can also turn to its Patch Rewards Program, which offers rewards for proactively improving the security of open source projects.

“We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027,” Google said.

[ Read: Will AI Kill the Bug Bounty Industry? ]

Introduced in 2022, the OSS VRP pays researchers for vulnerabilities found in Google’s open source projects.

The OSS VRP pause follows changes Google made in May to its Chrome and Android reward programs, in response to the growing use of AI tools for vulnerability discovery. 

Standard Chrome payouts were reduced, as the company began favoring concise reports that provide concrete proof a bug exists. For Android, Google said it would prioritize vulnerability types that are harder for AI tools to find, and the top reward for a zero-click Pixel Titan M exploit with persistence went from $1 million to $1.5 million.

In March, the Internet Bug Bounty (IBB) program run by HackerOne paused new submissions, saying the speed and volume of AI-assisted vulnerability discoveries had outpaced the open source community’s ability to deliver fixes.

Related: Google Paid Out $17 Million in Bug Bounty Rewards in 2025

Related: Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

Related: OpenAI Launches Bug Bounty Program for Abuse and Safety Risks

Related Content

Artificial Intelligence

The announcement comes after Trump hosted top executives of AI companies at the White House last week.

Cybersecurity Funding

doxx.net’s new ADN platform prevents agentic misadventure while the agent is operating under the user’s authority.

Artificial Intelligence

The attacks targeted the US Department of Education and Library and Archives Canada, and researchers linked some agents to OpenAI.

Artificial Intelligence

Fifteen years after coining the framework, John Kindervag insists zero trust still works in the AI era—if you get the implementation right.

Data Protection

PwC’s survey found that only 22% of leaders would use fully autonomous AI for cyber defense, while just 21% are implementing quantum-resistant security measures.

Artificial Intelligence

As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals.

Artificial Intelligence

The flaws were chained to hijack sessions, achieve remote code execution, and elevate privileges to root.

Artificial Intelligence

The company says its new frontier AI model found a critical vulnerability in software used by hospitals worldwide.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version