AI Weekly Malaysia

Back to items Summaries

Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports

ID
32242
Status
summarized
Published
06 Oct 2026, 5:21 PM
Fetched
06 Oct 2026, 7:28 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/10/google-pauses-oss-product-bug-bounty.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
6.0
Created
06 Oct 2026, 7:29 PM
Tags
Audience
developers

What happened

Google has stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP) as of October 1, 2026, citing a significant rise in automated submissions that are mostly invalid. The pause affects product flaws in flagship and important projects like Go, Angular, Flutter, Bazel, and Protocol Buffers, and Google removed the listed rewards of $500–$7,500 for flagship and $101–$3,133.7 for important projects. Supply-chain compromise reports are still accepted with rewards up to $31,337, and Google promises an update in Q1 2027 but gave no date to resume product vulnerability rewards.

Why it matters

If you rely on Go, Angular, Flutter, Bazel, or Protocol Buffers, Google's bounty no longer financially incentivizes third-party reporting of product vulnerabilities in those repos, so you may need to budget for your own dependency security or rely on other disclosure channels. If you're a security researcher, submitting product vulnerabilities to OSS VRP now yields no reward; supply-chain reports still pay, with flagship rewards at $3,133.7–$31,337.

Discussion angle

Does pausing product vulnerability rewards risk leaving known flaws in widely used OSS unreported, and should maintainers adopt alternative disclosure incentives or stricter report triage?

Top