Google has paused its Open Source Software Vulnerability Rewards Program (OSS VRP) due to what the company described as a significant rise in automated, AI-generated submissions. The pause took effect on October 1, 2026, and Google said it plans to provide an update in the first quarter of 2027.
WHAT THE OSS VRP COVERS AND ITS HISTORY
The OSS VRP incentivizes security researchers to responsibly disclose vulnerabilities in Google-maintained open-source software and related components, including projects like Golang, Angular, Bazel, Protocol Buffers, and Fuchsia, as well as various repository settings and dependencies. TechStaged has also covered Google Antigravity and Gemini 3.7 Flash accelerate multi-agent problem solving across math and engineering.
The program was launched in August 2022, with rewards ranging from $100 to $31,337 and a focus on the most impactful issues for the software supply chain.
WHAT THIS MEANS FOR RESEARCHERS AND HOW TO PROCEED
Google says the pause does not affect OSS VRP supply chain reports or any outstanding reports. During the pause, researchers can still submit security patches via the Google Patch Rewards Program (rewards up to $15,000 for high-impact fixes) and report vulnerabilities in Google Cloud open-source repositories through the Cloud VRP.
Google is working on readjusting the OSS VRP to address automated-submission concerns and will announce changes in 2027.
NEXT STEPS AND TIMING
Google indicated that it would provide an update in Q1 2027 and that the OSS VRP would be reformatted to address the influx of invalid automated submissions. In the meantime, researchers are encouraged to explore other VRP programs or pursue the Patch Rewards Program for eligible issues.
BROADER CONTEXT AND PAST WARNINGS
Industry observers have warned that AI-generated reports and AI-assisted tooling can overwhelm bug bounty programs, a trend that Google explicitly cited as a driver for the pause. Other companies have faced similar pressures as AI tooling becomes more capable at scanning and reporting potential vulnerabilities.
RELATED COVERAGE
- Google Antigravity and Gemini 3.7 Flash accelerate multi-agent problem solving across math and engineering
- OpenStamp: A Watermark for Open-Source Language Models Emerges in arXiv Paper
- ArXiv Preprint Examines Privacy in Mental Health Apps
- MetaRoCE: Meta Unveils a New RDMA Transport for AI-Scale Ethernet with Open-Source Roadmap
- Software articles






