Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports
- ID
- 32242
- Status
- summarized
- Published
- 06 Oct 2026, 5:21 PM
- Fetched
- 06 Oct 2026, 7:28 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/10/google-pauses-oss-product-bug-bounty.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.0
- Created
- 06 Oct 2026, 7:29 PM
- Tags
- Audience
- developers
What happened
Google has stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP) as of October 1, 2026, citing a significant rise in automated submissions that are mostly invalid. The pause affects product flaws in flagship and important projects like Go, Angular, Flutter, Bazel, and Protocol Buffers, and Google removed the listed rewards of $500–$7,500 for flagship and $101–$3,133.7 for important projects. Supply-chain compromise reports are still accepted with rewards up to $31,337, and Google promises an update in Q1 2027 but gave no date to resume product vulnerability rewards.
Why it matters
If you rely on Go, Angular, Flutter, Bazel, or Protocol Buffers, Google's bounty no longer financially incentivizes third-party reporting of product vulnerabilities in those repos, so you may need to budget for your own dependency security or rely on other disclosure channels. If you're a security researcher, submitting product vulnerabilities to OSS VRP now yields no reward; supply-chain reports still pay, with flagship rewards at $3,133.7–$31,337.
Discussion angle
Does pausing product vulnerability rewards risk leaving known flaws in widely used OSS unreported, and should maintainers adopt alternative disclosure incentives or stricter report triage?