- Google has temporarily paused product vulnerability submissions for its Open Source Software VRP due to a surge in invalid reports.
- The suspension, effective October 1, removes bounties for flaws in flagship projects like Go, Angular, and Protocol Buffers, though supply chain and “other” security reports remain rewarded.
- Researchers are directed to alternative channels like the Cloud VRP, Patch Rewards Program, or other Google programs while the OSS VRP is reworked.
- Google has pledged an update on the program’s future by the first quarter of 2027.
Google has temporarily halted submissions of product vulnerability reports for its open-source software bug bounty program, a decision announced on October 1. The move, which Google confirmed via a post on X, stems from “a significant rise in automated submissions, the vast majority of which are not valid,” prompting the company to pause this specific category while it reworks the program.
The suspension applies to design or implementation flaws in software built with Google’s open-source code, such as Go, Angular, and Protocol Buffers, which previously offered rewards ranging from $500 to $7,500 for its top-tier projects. However, reports about supply chain compromises, where attackers could tamper with source code, still qualify for bounties, with flagship projects paying between $3,133.7 and $31,337. The updated program rules on Bug Hunters now show no listed amounts for product vulnerabilities, and Google has committed to communicating an update by the first quarter of 2027.
Consequently, researchers seeking rewards for product flaws have three alternative routes. The Cloud VRP may accept reports for certain Google Cloud repositories, while the Patch Rewards Program offers $100 to $15,000 for accepted security patches rather than vulnerability reports.
Meanwhile, Google’s tiered repository list, updated in mid-September, still identifies 26 flagship projects, including Flutter and Bazel, but the notice does not clarify whether product vulnerability reports will be accepted without compensation. Notably, Go’s security policy encourages direct email reports, while Angular’s policy continues to direct researchers to Google’s Bug Hunters platform. The pause follows a March 2026 rule update requiring stronger proof of vulnerabilities, a response to a rise in low-quality, often AI-generated submissions, as previously reported.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
