ThinkFacility Sign in
  1. Home
  2. News
  3. Google

Google pauses its open-source bug bounty for product flaws, citing a flood of invalid automated reports

Most of what arrived was automated and invalid, Google says, and the pause runs until at least early 2027.

Google has stopped taking product bug reports through its open-source bug bounty. Its Google VRP account posted the pause on X at noon Eastern on October 1, 2026, and gave the reason in one line: most of what was arriving was automated, and most of that wasn't valid.

The pause has no end date. Google says it will give an update in the first quarter of 2027.

What stopped
OSS VRP product vulnerability submissions
Still open
OSS VRP supply chain reports, or any outstanding reports
Why
a significant rise in automated submissions
Next update
Q1 2027

What Google posted

The OSS VRP is Google's bounty for security bugs in its open-source projects. Here's the whole announcement.

A long white Google sign reading 1565 and 1585 Charleston Road, B45 and B46, under tall redwood trees
A Google campus sign on Charleston Road in Mountain View, California, 2022. Photo: Dietmar Rabich, CC BY-SA 4.0, via Wikimedia Commons
Google VRP (Google Bug Hunters)@GoogleVRP

📢 PSA for open-source bug hunters We are temporarily no longer accepting OSS VRP product vulnerability submissions. This does not impact OSS VRP supply chain reports, or any outstanding reports. As an alternative, we encourage you to find impact across our other VRP programs and submit there instead, or pursue the Patch Rewards Program. Why is this happening? This pause is due to a significant rise in automated submissions, the vast majority of which are not valid. We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027. https://t.co/nQEkHVfbHS

View the post on X

Two kinds of report survive. Supply chain reports are still accepted, and anything already filed before the pause keeps moving. Everyone else is pointed at Google's other reward programs, or at its Patch Rewards Program (the post names that one, and no other, by name).

Why it matters

A bug bounty only works if the people triaging it can keep up. Google's post doesn't give numbers, so there's no way to tell from it how many reports came in or how few held up. It says "the vast majority" of the automated ones were invalid, and that's all.

The word it uses is automated. I'd read that as reports written by AI tools and sent in bulk, which is how much of the press covered it, but Google's own post doesn't say AI anywhere.

This pause is due to a significant rise in automated submissions, the vast majority of which are not valid.

Google VRP (Google Bug Hunters)

For a researcher who finds a real bug in a Google open-source product this week, the post gives one practical route: look for impact in another Google program and file there. Google didn't say which programs would take open-source product bugs, or whether payouts change.

Google says the next word on this part of the OSS VRP comes in Q1 2027.

More on Google

All Google stories