Security & privacy

Google pauses rewards for open source product bugs amid automated report surge

Google has temporarily stopped paying for product vulnerability reports in its open source bug bounty program due to a spike in invalid automated submissions.

A scale balancing a reward coin against spam papers with a robotic hand nearby
Illustration generated for this article

Google has suspended monetary rewards for product vulnerability reports in its Open Source Software Vulnerability Reward Program (OSS VRP). The change took effect on October 1, 2026, affecting major projects like Go, Angular, and Protocol Buffers. The company cited a significant increase in automated, invalid submissions as the primary reason for the pause.

What happened

The suspension applies specifically to product vulnerabilities, which are defined as design or implementation flaws that substantially affect data confidentiality or integrity. This includes issues like memory corruption in file parsers or path traversal errors. Previously, researchers could earn between $500 and $7,500 for flagship projects and $101 to $3,133.7 for important projects. These reward tiers have now been removed from the program rules.

Google announced the change via a post on X on October 1, describing the halt as temporary. The company stated it would rework this part of the program and provide an update in the first quarter of 2027. No specific date was given for when product vulnerability rewards will resume. The policy update was published to Google’s public GitHub repository on September 30, one day before the public announcement.

While product vulnerability rewards are paused, other categories remain active. Rewards for supply chain compromises, such as tampering with source code or published packages, are still available. Leaked credentials that grant write access also continue to qualify for payments. Reports filed before October 1 are not affected by this change and will be processed under the previous rules.

How it works

The OSS VRP categorizes projects into four tiers based on sensitivity: flagship, important, standard, and low-priority. Only the top two tiers previously offered rewards for product vulnerabilities. The program now directs researchers to alternative channels for reporting these specific types of flaws. For instance, some Google Cloud repositories may still accept product vulnerability reports through the Cloud VRP, though caps apply.

Another alternative is the Patch Rewards Program, which pays between $100 and $15,000 for accepted security patches rather than just reports. To qualify, a patch must be merged by project maintainers and remain in place for one month. This shifts the burden of proof from theoretical vulnerability description to actual code remediation. Researchers are also encouraged to check if their findings affect other Google products covered by different reward programs, such as the AI VRP.

The rise in invalid reports has led to stricter filtering measures. In March 2026, Google began requiring stronger proof for reports in certain tiers, such as a merged patch. The Go project recently updated its security policy to address large language model (LLM) generated reports. It explicitly asks researchers to review and filter LLM output before submission, noting that while AI can find real bugs, it is equally proficient at inventing non-existent ones.

Key details

  • The pause on product vulnerability rewards started on October 1, 2026, and is temporary.
  • Supply chain compromise rewards remain active, ranging from $500 to $31,337 depending on the tier.
  • Flagship projects like Go, Angular, Flutter, Bazel, and Protocol Buffers are affected by the pause.
  • Google plans to release an update on the program's status in the first quarter of 2027.
  • The Patch Rewards Program remains an option, paying for merged and sustained security fixes.
  • Unfiltered LLM-generated reports may result in loss of credit for findings in projects like Go.

Why it matters

For security researchers and ethical hackers, this change significantly alters the incentive structure for auditing Google’s open source ecosystem. The removal of predictable payouts for product vulnerabilities means that independent auditors must either shift their focus to supply chain issues or invest more effort in creating and submitting actual patches. This raises the barrier to entry, potentially reducing the volume of reports but ideally increasing their quality.

For engineering teams maintaining open source projects, this shift highlights the growing challenge of managing automated noise in security channels. The reliance on AI tools for vulnerability scanning has created a flood of low-quality data that consumes triage resources. By pausing rewards, Google is signaling that the current model is unsustainable without better filtering mechanisms. This may prompt other organizations to rethink how they handle automated submissions in their own bug bounty programs.

What you can do

  • Review your current targets and prioritize supply chain security assessments, as these rewards remain active.
  • If you find a product vulnerability, consider developing a full patch and submitting it through the Patch Rewards Program.
  • Filter any AI-generated vulnerability reports manually before submission to avoid being disqualified for low quality.
  • Check if the vulnerability affects Google Cloud or AI products, which may still offer rewards through their specific VRPs.
  • Monitor Google’s official channels for updates in the first quarter of 2027 regarding the resumption of product rewards.
  • Consult individual project security policies, such as Go’s email-based reporting, for alternative submission routes.

Tools from the Bytechap store

Keep reading

All stories