Particle.news

Google Pauses Open-Source Bug Bounty Program

The company took the step in response to a flood of low-quality automated reports that overwhelmed human reviewers, and it plans a program rework with an update due in Q1 2027.

Overview

  • Google stopped accepting product vulnerability submissions to its Open Source Software Vulnerability Reward Program on Thursday, October 1, 2026, while continuing to process reports filed before that date and still taking supply-chain reports.
  • The pause follows a large surge of automated, often AI-generated reports that contained hallucinated or low-impact issues and created a heavy manual triage burden for engineers and open-source maintainers.
  • Google is directing researchers to other channels including its Cloud Vulnerability Reward Program for some repositories and the Patch Rewards program that pays for verified code fixes.
  • The move mirrors actions by other projects and vendors that faced similar floods of fake reports, such as curl ending its HackerOne bounty, Linux maintainers reporting overload, and Intel removing some bounties.
  • Google tightened OSS VRP evidence rules earlier in 2026 and now plans to reformat submission and triage rules by Q1 2027, options under discussion include stronger proof-of-concept requirements, merged-patch incentives, rate limits, and automated pre-filtering.