Google Pauses Open-Source Bug Bounty as Automated Reports Flood the Inbox
Google has paused its open-source bug bounty program until 2027, saying it needs to stem a flood of AI-driven submissions. In a statement posted on social media on October 1, the company pointed to "a significant rise in automated submissions, the vast majority of which are not valid."
The Open Source Vulnerability Rewards Program (OSS VRP) launched in August 2022 and pays security researchers for finding flaws in Google's open-source projects. It covers the latest versions of software in Google's public GitHub repositories, selected repositories on other platforms, and repository settings such as GitHub Actions workflows and access control rules. Rewards range from $100 to $31,337, depending on severity and the importance of the project. Flaws closely tied to Google Cloud or AI products are already routed to separate reward programs.
The pause does not affect supply-chain reports or any reports already submitted. Google plans to "reformat" the program and expects to share an update in the first quarter of 2027. In the meantime, it encourages researchers to submit findings through its other reward programs or pursue its Patch Rewards Program.