Trending:

Google pauses open-source bug bounty program amid surge of AI-submitted reports

Screenshot-style illustration of a paused bug bounty program interface
TechStaged-owned

Summary

  • Google paused its Open Source Software Vulnerability Rewards Program (OSS VRP) as of October 1, 2026, citing a significant rise in automated AI submissions.
  • The pause does not affect OSS VRP supply chain reports or any outstanding reports.
  • Google plans to provide an update in Q1 2027 regarding changes to the OSS VRP.

Google has paused its Open Source Software Vulnerability Rewards Program (OSS VRP) due to what the company described as a significant rise in automated, AI-generated submissions. The pause took effect on October 1, 2026, and Google said it plans to provide an update in the first quarter of 2027.

WHAT THE OSS VRP COVERS AND ITS HISTORY

The OSS VRP incentivizes security researchers to responsibly disclose vulnerabilities in Google-maintained open-source software and related components, including projects like Golang, Angular, Bazel, Protocol Buffers, and Fuchsia, as well as various repository settings and dependencies. TechStaged has also covered Google Antigravity and Gemini 3.7 Flash accelerate multi-agent problem solving across math and engineering.

The program was launched in August 2022, with rewards ranging from $100 to $31,337 and a focus on the most impactful issues for the software supply chain.

WHAT THIS MEANS FOR RESEARCHERS AND HOW TO PROCEED

Google says the pause does not affect OSS VRP supply chain reports or any outstanding reports. During the pause, researchers can still submit security patches via the Google Patch Rewards Program (rewards up to $15,000 for high-impact fixes) and report vulnerabilities in Google Cloud open-source repositories through the Cloud VRP.

Google is working on readjusting the OSS VRP to address automated-submission concerns and will announce changes in 2027.

NEXT STEPS AND TIMING

Google indicated that it would provide an update in Q1 2027 and that the OSS VRP would be reformatted to address the influx of invalid automated submissions. In the meantime, researchers are encouraged to explore other VRP programs or pursue the Patch Rewards Program for eligible issues.

BROADER CONTEXT AND PAST WARNINGS

Industry observers have warned that AI-generated reports and AI-assisted tooling can overwhelm bug bounty programs, a trend that Google explicitly cited as a driver for the pause. Other companies have faced similar pressures as AI tooling becomes more capable at scanning and reporting potential vulnerabilities.

Reporting by Ivy Whitmore; editing by TechStaged editors

Editorial disclosure: This article was prepared with AI assistance from a source-limited research package and passed TechStaged's automated factual, originality, licensing, and publication checks.

Our Standards: The TechStaged Editorial Principles.

Suggested Topics: Software Business Software
f in

Ivy Whitmore

Ivy Whitmore

Business Software Guide

Ivy writes practical guides for choosing, implementing, and comparing core business software.