Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports
Description
Google has temporarily paused accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP) due to a surge in invalid automated submissions. This pause affects only product vulnerability reports and does not impact supply chain reports or pending submissions. Google encourages researchers to submit vulnerabilities through other programs such as the Cloud VRP or Patch Rewards Program. The company plans to revisit and update the OSS VRP in early 2027. This action follows similar adjustments in Google's Chrome and Android bug bounty programs in response to increased AI-assisted vulnerability discovery.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Google's OSS VRP, launched in 2022 to reward vulnerabilities in its open source projects, has been temporarily closed to new product vulnerability submissions as of October 1, 2026. The closure is a response to a significant rise in automated vulnerability reports, most of which are invalid. This measure is limited to product vulnerabilities and excludes supply chain vulnerability reports and any reports submitted before the pause. Google directs researchers to other reward programs for submitting valid findings and plans to reform the OSS VRP with an update expected in Q1 2027. This pause aligns with broader industry trends addressing the impact of AI tools on vulnerability discovery and reporting.
Potential Impact
The temporary suspension of product vulnerability submissions to the OSS VRP may slow the intake of new vulnerability reports for Google's open source projects, potentially delaying identification and remediation of new product vulnerabilities through this channel. However, supply chain vulnerability reports and pending submissions remain unaffected. Researchers still have alternative avenues to report vulnerabilities impacting Google Cloud products and open source projects. There is no indication of active exploitation or increased risk due to this pause.
Defensive Guidance
No direct mitigation is required by defenders as this is an operational change by Google in its vulnerability reward program. Researchers should submit product vulnerability reports through alternative Google programs such as the Cloud VRP or Patch Rewards Program. Organizations relying on OSS VRP reports should monitor updates from Google, with a planned update expected in Q1 2027. There is no impact on existing reports or supply chain vulnerability submissions.
Technical Details
- Classification
- {"confidence":0.59,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/google-narrows-open-source-bug-bounty-amid-wave-of-invalid-automated-reports/","fetched":true,"fetchedAt":"2026-10-05T14:33:19.443Z","wordCount":1096}
Threat ID: 6ac3b5302cdf04f6560becdf
Added to database: 10/05/2026, 14:33:20 UTC
Last enriched: 10/05/2026, 14:33:25 UTC
Last updated: 10/05/2026, 20:33:19 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.