Google Suspends Open Source Bug Rewards Amid Rise In Invalid Automated Submissions

Published:

Google has temporarily paused product vulnerability rewards under its Open Source Software Vulnerability Reward Program (OSS VRP) following a significant increase in automated submissions that the company said were mostly invalid. The change, which came into effect on October 1, prevents security researchers from submitting certain product vulnerability reports for rewards in open source projects including Go, Angular, Flutter, Bazel, and Protocol Buffers. Google said the decision is temporary and is part of an effort to review and improve this section of the program. Reports related to supply chain compromises remain eligible, while vulnerability submissions made before October 1 are not affected by the change.

In an announcement shared on X, Google stated that the pause was introduced due to a rise in automated reports, with the majority of submissions found to be invalid. The company did not provide specific figures regarding the number of reports received or confirm whether artificial intelligence tools were responsible for generating the submissions. The OSS VRP rules have been updated with a notice explaining the temporary suspension, and Google has indicated that it plans to provide further updates during the first quarter of 2027 while reviewing the program structure. However, the company has not announced a specific date for when product vulnerability reward submissions will resume. Under the program rules, product vulnerabilities refer to design or implementation issues in Google maintained open source software that could significantly impact user data confidentiality or integrity. Examples include memory corruption vulnerabilities in file format parsers and path traversal issues.

Before the pause, the OSS VRP categorized projects into different tiers based on their importance and security sensitivity. Reward amounts were previously available for product vulnerabilities affecting flagship and important projects. The listed rewards included payments ranging from $500 to $7,500 for flagship projects and between $101 and $3,133.70 for important projects. These reward listings have now been removed from the program rules. Google’s tiered repository list includes 26 flagship repositories and 47 important repositories, with major projects such as Go, Angular, Flutter, Bazel, and Protocol Buffers included among the higher priority categories. While product vulnerability rewards have been paused, other security categories continue to maintain reward structures. Supply chain compromises, which involve attempts to modify source code or published software packages, remain eligible for rewards. Other security issues, including exposed credentials that provide write access, also continue to be covered under existing reward categories.

Google has outlined alternative options for researchers who identify security issues during the pause. Some product vulnerability reports may still qualify under Google Cloud Vulnerability Reward Program if they affect Google Cloud products connected to open source repositories. Researchers can also submit security patches through Google’s Patch Rewards Program, which provides payments for accepted security improvements rather than vulnerability reports. In addition, Google has encouraged researchers to review whether identified issues fall under other reward programs, including Cloud VRP or AI VRP. The company’s decision follows earlier efforts to improve report quality within the OSS VRP. In March 2026, Google introduced stronger proof requirements for certain reports after concerns about low quality submissions. Security teams have also raised concerns about unverified reports generated through large language models, with projects such as Go advising researchers to review and filter AI generated findings before submission. The latest pause highlights the increasing challenge faced by bug bounty programs in managing large volumes of automated security reports while maintaining effective channels for genuine vulnerability research.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Related articles

spot_img