Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

Google has temporarily shut down its Open Source Software Vulnerability Reward Program (OSS VRP) for product vulnerability submissions, citing a surge in automated reports that have overwhelmed the system. This move affects researchers who had been relying on the program to receive rewards for discovering vulnerabilities in Google’s open source projects.

The pause, which was announced on October 1, is not a complete shutdown of the OSS VRP, but rather a temporary measure to address the issue of invalid automated reports. According to Google, only product vulnerabilities are covered by this change, and it has no impact on supply chain reports or pending reports already submitted before October 1.

The problem lies in the fact that many of these automated reports are not valid, which can lead to wasted time and resources for both researchers and the company’s security teams. In an effort to combat this issue, Google is urging bug hunters to look for vulnerabilities that have a significant impact on its products and submit their findings through other programs.

The OSS VRP was introduced in 2022 as part of Google’s efforts to improve the security of open source projects. The program pays researchers for discovering vulnerabilities in Google’s open source code, with rewards ranging from $1,000 to $10,000 or more depending on the severity and impact of the vulnerability.

This move by Google follows a trend of changes made by major tech companies in response to the growing use of AI tools for vulnerability discovery. In May, Google reduced standard Chrome payouts and began favoring concise reports that provide concrete proof of a bug’s existence. It also prioritized vulnerability types that are harder for AI tools to find.

The Internet Bug Bounty (IBB) program run by HackerOne took a similar step in March, pausing new submissions due to the speed and volume of AI-assisted vulnerability discoveries outpacing the open source community’s ability to deliver fixes.

While this pause may seem like a setback for researchers, it also presents an opportunity for them to explore other programs that offer rewards for discovering vulnerabilities. Google is encouraging bug hunters to turn their attention to its Patch Rewards Program, which offers incentives for proactively improving the security of open source projects.

In the long run, this move by Google may lead to more efficient and effective vulnerability discovery, as well as a greater focus on finding high-impact vulnerabilities that require urgent attention. As AI tools continue to play an increasingly important role in vulnerability discovery, it’s clear that companies like Google are adapting their programs to stay ahead of the curve.

For readers interested in bug hunting, this development serves as a reminder to be mindful of the changing landscape and to explore alternative programs that may offer better rewards or more flexible submission guidelines. By staying informed about these changes, researchers can continue to play an essential role in securing open source software and protecting users from vulnerabilities.


Source: SecurityWeek — 2026-10-05