As of October 1, Google has temporarily stopped reporting new product vulnerabilities in the OSS VRP bug bounty program for open source projects. The company’s vulnerability bounty approach continues; The change only covers certain applications of the open source program.
Google says that notifications generated by automated tools and generative artificial intelligence have increased significantly. Since the majority of these applications are invalid, the time the security team allocates to qualified reports is decreasing.
The program introduced new rules that increased the quality of evidence in March 2026. Despite this, the volume of low-quality notifications did not decrease. The company now plans to revise the evaluation process and application requirements.
During the pause, evaluation of previously submitted reports will continue. Other Google Bug Bounty Programs will also remain open. Therefore, general application channels for valid security vulnerabilities in Google products are not closed.
The program will be updated in the first quarter of 2027
Google states that the new structure in OSS VRP will be announced in the first quarter of 2027. The company has not yet shared what changes will be made to reward amounts or acceptance criteria.
This decision focuses on report quality rather than the utility of AI-powered security tools. In addition, sending the automatic scanning result without verifying it affects both the reputation of the researcher and the operation of the program. The new rules can be expected to more explicitly call for reproducible evidence and real impact.