Google Halts Product Vulnerability Submissions in Open Source Bug Bounty Program
Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program, citing an influx of AI-generated submissions. Supply chain reports and submissions made before October 1 remain unaffected.

For researchers hunting security flaws in Google's open source projects, the Open Source Software Vulnerability Reward Program (OSS VRP) has served as the official channel since 2022. The program covered codebases including Flutter, Angular, Go, and Fuchsia. That pathway has now narrowed: Google announced via X that it is discontinuing the product-facing component of the initiative.
The company characterizes the suspension as temporary. Reports addressing supply chain vulnerabilities will continue to be accepted, and any submissions filed before October 1 remain valid and unaffected by the change.
What's closed, what's not?
📢 PSA for open-source bug huntersWe are temporarily no longer accepting OSS VRP product vulnerability submissions. This does not impact OSS VRP supply chain reports, or any outstanding reports. As an alternative, we encourage you to find impact across our other VRP programs…
Google VRP (@GoogleVRP), October 1, 2026
Product vulnerabilities encompass defects within the projects themselves—such as flawed HTML sanitizers, memory corruption in file format parsers, or unsafe code samples in documentation. The new restrictions apply universally across all project tiers without exception.
Supply chain vulnerabilities operate on a different plane, addressing weaknesses in the construction and distribution mechanisms of software. An example cited in the rules involves exposed credentials for package managers that could be exploited to distribute compromised build artifacts. These reports face no restrictions under the new policy.
Google Cloud repositories represent a partial exception. When a vulnerability in these repositories affects a Cloud product directly, Google may still evaluate the submission through its separate Cloud VRP channel.
Why did it come to this?
The underlying cause traces back to March, when Google engineers posted on the Bug Hunters blog about a deluge of AI-generated submissions overwhelming the program. Many contained fabricated details, while others identified genuine coding mistakes with negligible security consequences for the affected projects.
Google's initial response tightened requirements for memory corruption findings in its highest-tier projects. Researchers submitting such reports needed either to demonstrate the bug using an existing OSS-Fuzz target or reference a patch that project maintainers had already integrated.
A subsequent update to the same blog post escalated the restrictions further. The lower-tier categories, designated OT2 and OT3, ceased offering monetary rewards or recognition for product vulnerabilities and related security issues. The maximum supply chain reward for OT2 projects also declined to $3,133.70.
Supply chain submissions continue to generate payments, ranging from $500 for OT2 projects to $31,337 for flagship initiatives. As a substitute avenue, Google directs researchers toward the Patch Rewards Program, which offers $100 to $15,000 for patches that remain unreverted in a project for a minimum of one month.
An open question
Google has provided no timeline or specifics regarding the resumption of product vulnerability submissions. The company's statement commits only to providing an update during the first quarter of 2027 as it continues refining this segment of the program.
One inconsistency persists: the OSS VRP webpage still displays reward brackets for product vulnerabilities reaching $7,500, even though the accompanying rules page has already been updated to reflect the suspension. Alignment between these pages is expected soon.