The OSS VRP, launched in August 2022, incentivised researchers to disclose security flaws in Google-maintained open-source projects such as Golang, Angular, Bazel, Protocol Buffers, Fuchsia, and critical third-party dependencies. Rewards ranged from $100 to $31,337.
Google stated on X that it is temporarily not accepting OSS VRP product vulnerability submissions. The pause does not affect supply chain reports or any outstanding submissions made before October 1, 2026. Researchers can still submit security patches through the Google Patch Rewards Program, which offers bounties of up to $15,000, and report vulnerabilities in Google Cloud open-source repositories via the Cloud VRP.
The company said it is working to address the automated submission issues and will provide an update in Q1 2027.
Google is not the first to shut down a bug bounty program because of poor-quality AI-generated reports. In January 2026, the maintainer of the curl utility ended its bug bounty program after a similar flood of AI-generated reports.
Since launching its first Vulnerability Rewards Program in 2010, Google has paid over $81.6 million to thousands of security researchers. In 2025, it awarded a record $17.1 million to more than 700 researchers, a 40% increase from 2024.