Google just froze a big part of its Google bug bounty lineup. Since October 1, its Open Source Software Vulnerability Rewards Program (OSS VRP) no longer takes new product vulnerability reports, because AI tools buried the team in junk submissions. If you hunt bugs in Go, Angular, or other Google open-source projects, you’ll need a different route until at least early 2027.
Here’s what you need to know in ten seconds.
- Paused since: October 1, 2026, for new product vulnerability reports.
- Why: a flood of automated reports, most of them invalid, per Google.
- Projects hit: Go, Angular, Bazel, Protocol Buffers, Fuchsia, and key third-party dependencies.
- Still open: the Patch Rewards Program, the Cloud VRP, and OSS VRP supply chain reports.
- Next update: Google says it will share news in Q1 2027.
What Google Actually Said About the Pause
Google’s notice is short and blunt. It says it is “temporarily no longer accepting OSS VRP product vulnerability submissions” because of “a significant rise in automated submissions, the vast majority of which are not valid.”
In plain terms, people pointed AI tools at Google’s code, let them spit out “findings,” and sent them in without checking. Each report still needs a human to read, test, and reject it. When most of the pile is noise, the real bugs get stuck in the queue.
Reports sent before October 1 are not affected. If you already have something in review, it keeps moving as normal.
Which Parts of the Google Bug Bounty Program Are Still Open
This is not a full shutdown of every Google reward. The pause targets one slice of the OSS VRP. The table below shows where things stand, based on BleepingComputer’s breakdown of Google’s notice.
| Program | Status | What it covers |
|---|---|---|
| OSS VRP (product vulnerabilities) | Paused | Security bugs in Go, Angular, Bazel, Protobuf, Fuchsia and more |
| OSS VRP (supply chain) | Open | Compromised builds, repos, and release pipelines |
| Patch Rewards Program | Open | Security fixes you write for open-source projects, up to $15,000 |
| Cloud VRP | Open | Google Cloud open-source repositories |
Google’s notice doesn’t mention Chrome or Android. Those run as separate reward programs, so this freeze isn’t about them.
Why AI-Generated Reports Became a Real Problem
The OSS VRP launched in August 2022 and paid from $100 up to $31,337 per bug. That’s a big carrot. Once AI coding tools got good at producing confident-sounding security write-ups, the cost of sending a report dropped to almost zero.
The trouble is that AI tools often “find” bugs that don’t exist. They misread code, invent function calls, or flag harmless patterns as exploits. A human can spot that, but only after spending real time on it.
Google isn’t the first to hit this wall. According to BleepingComputer, the curl project ended its HackerOne bounty in January 2026, and Intel stopped paid bounties in mid-September, both over low-quality AI reports. When a company with Google’s resources taps out too, it’s a clear sign the old model is breaking.
That doesn’t mean AI is useless for security work. Real flaws do turn up in AI tools themselves, like the GitHub Copilot CLI vulnerability we covered recently. The problem is unchecked output, not the tools.
What You Should Do If You Hunt Bugs
If you found a real issue in a Google open-source project, don’t sit on it. You still have options while the paid program is frozen.
- Check whether the bug fits the supply chain category, which is still open.
- Write a fix and submit it through the Patch Rewards Program.
- If it touches a Google Cloud repo, file it under the Cloud VRP.
- Otherwise, report it through the project’s normal security contact. You may not get paid, but users get protected.
And if you use AI to help you find bugs, verify every claim yourself. Build a working proof of concept, cite real lines of code, and cut anything you can’t reproduce. Clean, tested reports are what will matter most when Google relaunches.
Does This Make Open-Source Software Less Safe?
In the short term, maybe a little. Paid bounties pull skilled researchers toward a project. Taking the money away for a few months could mean fewer eyes on Go or Angular.
But a queue stuffed with fake reports wasn’t safe either. Real bugs were waiting behind hundreds of bad ones. A slower, cleaner process could end up catching more serious flaws, not fewer.
For everyday users, nothing changes today. Keep your apps and tools updated, as always. Security fixes still ship through normal updates, just like the recent Mistral Vibe patch did.
Frequently Asked Questions
Is Google’s bug bounty program shut down for good?
No. Google calls it a temporary pause on OSS VRP product vulnerability reports. It plans to share an update on the reworked program in Q1 2027.
Can I still report bugs in Chrome or Android?
The pause notice only covers the open-source program. Chrome and Android have their own reward programs, and Google’s announcement doesn’t list them as affected.
What happens to reports I sent before October 1?
They’re unaffected. Google says submissions received before October 1, 2026 continue through review as usual.
Why did AI reports cause the pause?
Automated tools sent a huge number of reports, and Google says most were invalid. Every report needs human review, so the noise slowed down real fixes.
Our Take
This pause is the right call, even if it stings for honest researchers. A bounty only works when reviewers can trust the queue, and right now they can’t. If you’re a bug hunter, use the next few months to sharpen your process: fewer reports, real proof, zero AI guesswork. The people who do that will be first in line when Google reopens the doors.


Leave a Reply