Google announced on 1 October 2026 that it is temporarily closing the product vulnerability side of its Open Source Software Vulnerability Reward Program, which since 2022 had paid outside researchers for security flaws in the company’s open source code including Flutter, Angular, Go and Fuchsia. It’s FOSS reports that supply chain reports, which cover how software is built and shipped, remain open, submissions made before 1 October are unaffected, and some Google Cloud repositories may still be reported through the Cloud VRP. Google engineers wrote in March that AI-generated reports were flooding the program with hallucinated findings and legitimate but low-impact coding errors, and the company first tightened memory corruption requirements and then stopped offering rewards or credit for product vulnerabilities in its OT2 and OT3 tiers, while cutting the top supply chain reward for OT2 projects to 3,133.70 dollars. Supply chain reports still pay from 500 dollars on OT2 projects up to 31,337 dollars on flagship ones, and Google pointed researchers to its Patch Rewards Program, which pays 100 to 15,000 dollars for patches that survive a month without being reverted. The company said it would update on the program in the first quarter of 2027.
Google shuts down product vulnerability reports in its open source bounty program
Google announced on 1 October 2026 that it is temporarily closing the product vulnerability side of its Open Source Software Vulnerability Reward Program, which since 2022 had paid outside researchers for security flaws in the company's open source code including Flutter, Angular, Go and Fuchsia. It's FOSS reports that supply chain reports, which cover how software is built and shipped, remain open, submissions made before 1 October are unaffected, and some Google Cloud repositories may still be reported through the Cloud VRP. Google engineers wrote in March that AI-generated reports were flooding the program with hallucinated findings and legitimate but low-impact coding errors, and the company first tightened memory corruption requirements and then stopped offering rewards or credit for product vulnerabilities in its OT2 and OT3 tiers, while cutting the top supply chain reward for OT2 projects to 3,133.70 dollars. Supply chain reports still pay from 500 dollars on OT2 projects up to 31,337 dollars on flagship ones, and Google pointed researchers to its Patch Rewards Program, which pays 100 to 15,000 dollars for patches that survive a month without being reverted. The company said it would update on the program in the first quarter of 2027.
Source: It's FOSS