Google’s Open-Source Bug Bounty Pause Leaves Supply-Chain Reports Open
The October 1 change stops one category of new reports rather than the entire program. Supply-chain findings remain eligible, and previously submitted product reports can still be reviewed.
Google stopped accepting new product-vulnerability reports through its Open Source Software Vulnerability Rewards Program on October 1, 2026, following a surge in invalid automated submissions.
The pause covers one part of OSS VRP
The change applies to the product-vulnerability route within the Open Source Software Vulnerability Rewards Program, commonly called OSS VRP. It does not suspend every Google vulnerability reward program, and it does not close every reporting category within OSS VRP.
Google attributed the decision to a substantial increase in automated reports and said most of those submissions were invalid. TechRadar linked the influx to AI-assisted vulnerability reporting, while Google described the underlying problem more broadly as automated submissions.
That difference in wording is important. Google did not say that every rejected report was generated by artificial intelligence. Its explanation was that automation had driven up the volume of reports and that the majority failed to qualify as valid findings. AI tools form part of the reported context, but Google identified the larger operational issue as automated intake.
The pause acts at the point where researchers submit new product findings. A report that proves invalid still has to be received and assessed before it can be rejected, so a higher volume can increase the amount of screening required without producing a corresponding supply of actionable vulnerabilities. Google has responded by closing that submission path temporarily while it works on the affected portion of the program.
The measure took effect immediately on October 1. Tom’s Hardware reported that the change does not apply retroactively to product-vulnerability reports filed before that date. Those existing reports remain outside the suspension rather than being canceled or removed from consideration.
This scope makes the decision narrower than a shutdown of Google’s open-source bug bounty operation. It changes which new reports can enter one channel, but it leaves other OSS VRP work in place. For researchers, the practical question is therefore not simply whether OSS VRP is open or closed. It is whether a finding belongs to the paused product category, the unaffected supply-chain category, or an existing report already in progress.

Which reports remain eligible or under review
The status of a report depends on its category and, for product vulnerabilities, when it was submitted. The distinctions determine whether Google is still accepting the finding through OSS VRP or whether it can continue handling a report already received.
| Report category | Current status | Effect of the pause |
|---|---|---|
| New OSS VRP product-vulnerability report | Paused | Google has not accepted new reports in this category through the affected channel since October 1, 2026. |
| OSS VRP product report submitted before October 1 | Unaffected | A report already in the program is not canceled by the pause and can remain under review. |
| OSS VRP supply-chain report | Still eligible | The suspension does not cover this reporting category. |
The supply-chain exception is particularly significant because it confirms that OSS VRP has not stopped receiving every kind of submission. Researchers can still submit reports in that category, while the program can continue processing outstanding product reports received before the cutoff.
Google has also pointed researchers toward its other vulnerability reward programs and the Patch Rewards Program when their work falls within those programs. That direction does not automatically make a paused OSS VRP product finding eligible somewhere else. Each alternative has its own scope, so the nature and impact of a finding still determine where it can be submitted.
The program change should also be distinguished from a vulnerability in a consumer Google service or device. Fastwebmedia previously covered a Google Assistant calendar-invite vulnerability affecting connected-home controls, which concerned a specific attack path. The OSS VRP pause instead changes the intake process used by researchers to report certain open-source product flaws.
What Google’s 2027 update will address
Google intends to reassess and rework the affected part of OSS VRP before providing an update in the first quarter of 2027. The stated timeline concerns a status update, not a guaranteed date for reopening product-vulnerability submissions.
The company has not announced a permanent end to this part of the program. It has also not confirmed that the paused channel will return at the beginning of 2027, that it will reopen in its previous form, or that its submission requirements will remain unchanged. The planned reassessment leaves room for Google to alter how new product reports are received or evaluated, but no specific replacement process has been detailed.
Until that update arrives, the October 1 boundary remains the central rule. New OSS VRP product-vulnerability submissions are paused, product reports filed before the change remain active, and supply-chain reports can still be submitted. That division preserves reporting options for some open-source security findings while Google addresses the volume and validity problems it associated with automated reports.
Featured image. Source: Pexels. Credit: RDNE Stock project. License: Pexels License.
Continue reading



