Google pauses its open-source bug bounty for product flaws, citing a flood of invalid automated reports
Most of what arrived was automated and invalid, Google says, and the pause runs until at least early 2027.
Google has stopped taking product bug reports through its open-source bug bounty. Its Google VRP account posted the pause on X at noon Eastern on October 1, 2026, and gave the reason in one line: most of what was arriving was automated, and most of that wasn't valid.
The pause has no end date. Google says it will give an update in the first quarter of 2027.
- What stopped
- OSS VRP product vulnerability submissions
- Still open
- OSS VRP supply chain reports, or any outstanding reports
- Why
- a significant rise in automated submissions
- Next update
- Q1 2027
What Google posted
The OSS VRP is Google's bounty for security bugs in its open-source projects. Here's the whole announcement.

📢 PSA for open-source bug hunters We are temporarily no longer accepting OSS VRP product vulnerability submissions. This does not impact OSS VRP supply chain reports, or any outstanding reports. As an alternative, we encourage you to find impact across our other VRP programs and submit there instead, or pursue the Patch Rewards Program. Why is this happening? This pause is due to a significant rise in automated submissions, the vast majority of which are not valid. We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027. https://t.co/nQEkHVfbHS
Two kinds of report survive. Supply chain reports are still accepted, and anything already filed before the pause keeps moving. Everyone else is pointed at Google's other reward programs, or at its Patch Rewards Program (the post names that one, and no other, by name).
Why it matters
A bug bounty only works if the people triaging it can keep up. Google's post doesn't give numbers, so there's no way to tell from it how many reports came in or how few held up. It says "the vast majority" of the automated ones were invalid, and that's all.
The word it uses is automated. I'd read that as reports written by AI tools and sent in bulk, which is how much of the press covered it, but Google's own post doesn't say AI anywhere.
This pause is due to a significant rise in automated submissions, the vast majority of which are not valid.
For a researcher who finds a real bug in a Google open-source product this week, the post gives one practical route: look for impact in another Google program and file there. Google didn't say which programs would take open-source product bugs, or whether payouts change.
Google says the next word on this part of the OSS VRP comes in Q1 2027.
More on Google
- Gemini Live's new Guided Vision mode tells blind users how to point their cameraOctober 1, 2026
- Gemini skills replace Gems in November: what changes and what doesn't carry overOctober 1, 2026
- Gemini 4 Argon is out to cyber defenders only, with paid API and Ultra nextOctober 1, 2026
- Google DeepMind can now watermark AI-designed proteins, and the mark survives in the physical moleculeSeptember 30, 2026