Security News

Google Pauses Open-Source Bug Bounty as Automated Reports Flood the Inbox

Infosecurity Magazine · 5 Oct 2026
Key Takeaway If your business publishes or relies on open-source software, plan for slower vulnerability reporting and keep checking for security updates rather than assuming problems will be flagged quickly.

Google has paused its open-source bug bounty program until 2027, saying it needs to stem a flood of AI-driven submissions. In a statement posted on social media on October 1, the company pointed to "a significant rise in automated submissions, the vast majority of which are not valid."

The Open Source Vulnerability Rewards Program (OSS VRP) launched in August 2022 and pays security researchers for finding flaws in Google's open-source projects. It covers the latest versions of software in Google's public GitHub repositories, selected repositories on other platforms, and repository settings such as GitHub Actions workflows and access control rules. Rewards range from $100 to $31,337, depending on severity and the importance of the project. Flaws closely tied to Google Cloud or AI products are already routed to separate reward programs.

The pause does not affect supply-chain reports or any reports already submitted. Google plans to "reformat" the program and expects to share an update in the first quarter of 2027. In the meantime, it encourages researchers to submit findings through its other reward programs or pursue its Patch Rewards Program.

Google bug bounty open source AI vulnerability disclosure

Summarised by CISO AI from Infosecurity Magazine, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.