Connect with us

NEWS

Google Freezes OSS VRP Product Reports After AI Flood

Google paused OSS VRP product reports after invalid AI submissions, leaving real Go and Angular bugs without a paid private path until Q1.

Published

on

Google froze new product-vulnerability reports to its OSS VRP open-source bug bounty on October 1, 2026. The company said a rise in automated submissions, most of them invalid, had swamped the engineers and maintainers who read them. Supply-chain reports still pay. Product bugs in Go, Angular, and other flagship Google open source now sit outside that paid private path until a promised Q1 2027 update.

The freeze does not cut the volume of machine-written reports. It moves unpaid review onto Patch Rewards, Cloud VRP, and the same maintainers the bounty was built to give a queue.

Product Reports Stopped on October 1

Google Bug Hunters, posting as @GoogleVRP, said it is temporarily no longer accepting OSS VRP product-vulnerability submissions. Supply-chain reports are untouched. So are filings already in the queue. The live rules page is blunter still: the program is no longer accepting product vulnerabilities as of October 1, 2026.

“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” the official account wrote. It also said it will “reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027.” That is an update date. It is not a date the door reopens.

OSS VRP, launched in 2022, pays researchers who privately report flaws in Google-released open source, plus repository settings and supply-chain components. Flagship examples named in Google’s own 2026 rule update include Bazel, Angular, and Golang. Protocol Buffers sits in the same Google OSS bucket. A product vulnerability, in the program’s wording, is a design or implementation issue that substantially affects the confidentiality or integrity of user data in software builds that use that code.

The freeze is a category shutdown, not a program funeral. Hunters who only read the headlines will miss what is still in scope, and maintainers will still see the rest of the mail.

WHAT STILL GOES TO OSS VRP

  • Supply-chain reports: Flaws that let someone tamper with source, builds, or published packages still qualify, with cash still on the table.
  • Filings before October 1: Product reports already submitted keep moving through triage.
  • Other security issues: Credential leaks and similar non-product issues still pay at the two top project tiers.
  • Some Cloud repos: Product bugs that hit Google Cloud products may still go through Cloud VRP, and Google also points hunters at AI VRP.

Google’s VRP code of conduct already treats a high volume of unverified or out-of-scope reports as a violation, because that pattern “overwhelms the triage teams.” The pause is what happens when a conduct rule cannot keep up with the cost of generating a report.

A March Proof Bar That Did Not Hold

Google had already tried to starve junk without closing the door. The current OSS VRP rules, tightened in 2026, demand extra proof on the projects that pay the most. For memory-corruption bugs in OT0 and OT1 repositories, a hunter must hand over exact OSS-Fuzz reproduction steps on an existing fuzz target, including how to build the image, or show a patch already merged in the target repo. Non-memory-corruption bugs in those same tiers do not need a merged patch. OT2 and OT3 product bugs pay nothing.

Google Bug Hunters said the point of that bar was to let triage teams focus on the most serious threats, and to reward people who feed OSS-Fuzz rather than a ticket queue. OT0 and OT1 lists live at github.com/google/bughunters. Standard and low-priority projects never got a public roster; the panel picks the tier when it pays.

Those gates still left a human on the hook for every plausible-looking write-up. A model can now emit a polite, well-structured report that names functions and sketches an attack path. A maintainer still has to open the code, try to trigger it, and write the rejection. The proof rules raised the floor for a payout. They did not lower the cost of saying no.

GOOGLE’S 2026 OSS REWARD FREEZES

  1. March 2026: Tightens OSS VRP product-bug proof rules and stops paying OT2 and OT3 product reports.
  2. April 9, 2026: Puts the Tsunami Patch Rewards Program on hold for the foreseeable future.
  3. July 6, 2026: Puts the OSV-SCALIBR Patch Rewards Program on hold for the foreseeable future.
  4. October 1, 2026: Stops accepting new product-vulnerability reports to OSS VRP.
  5. Q1 2027: Google is due to give an update on the reformatted product-vuln track.

Read as a year, not a one-day shock, the October pause is the fourth time in 2026 Google has narrowed what it will pay to read. Each earlier cut left a smaller paid funnel. The funnel still clogged.

Where Real Bugs in Go and Angular Go Now

A researcher who finds a real product bug in Go, Angular, or another OT0 project after October 1 cannot sell that report to OSS VRP. Google tells them to look for impact in other VRP programs, or to pursue Patch Rewards. Cloud VRP may take some Google Cloud repositories. AI VRP is the named route for Google AI products. None of those programs is a drop-in replacement for a private, paid intake on Bazel or Protocol Buffers.

The unpaid path is the old one: mail the maintainers, open a GitHub security advisory, or drop a public issue. That is the path the bounty was supposed to keep noisy, low-quality mail out of. Close the paid private door and the same automated reports seek a human who cannot charge by the hour. Smaller projects outside Google’s payroll feel that first. Google’s own maintainers feel it next, because the code is public and the pause is not a robots.txt rule.

Report generation is now cheap enough that the economic test of a bounty flips. The program holds up only while writing a report costs more than reading one. Automated submissions broke that test. Google stopped paying to sit on the wrong side of it. The same company has already described AI agents compressing credential theft into hours, which is a different AI problem with the same shape: machines produce work at a speed human reviewers cannot staff.

Hunters with already-accepted product reports are in a worse bind than the pause language admits. At least one researcher replied to the official PSA to say a fixed issue had been waiting about seven months to be paid. New product filings now have no intake at all, while old ones can still sit in a slow queue. That is a second bill, paid by the people who did the work the program said it wanted.

Patch Rewards Pays for a Month-Old Merge

Patch Rewards is the door Google named twice, in the X post and on the rules page. It does not pay for a write-up. It pays for a change that is already in the tree. Qualifying work is typically a merged GitHub pull request that improved security on an in-scope project. Submissions are capped at 3 submissions per month per person, and the patch must be at least one month old so the panel can see that maintainers have not reverted it.

Those two limits are the filter OSS VRP just lost. A model can still draft a patch, but someone has to get it merged and wait a month. The Rewards Panel also may split the money with project maintainers when the review load is heavy. That last clause is a quiet admission that the scarce resource is maintainer time, not hunter time.

PATCH REWARD AMOUNTS BY TIER

Category Tier 1 Tier 2
S0, complicated high-impact fixes $15,000 $5,000
S1, moderately complex patches $7,500 $1,337
S2, modest or speculative gains $2,000 $500
S3, one-liner special $500 $100

Google says qualifying patch rewards range from $100 to $15,000, with the panel judging complexity, impact, and project tier. Through the end of 2026 it also offers a 2x multiplier for secure-by-design memory-safety work on tier 1 projects, and a 3x multiplier for that work on tier 1 projects scoped as core infrastructure data parsers. The 3x bump is not stacked on the 2x. One-liners are excluded from both multipliers. Unclaimed rewards are donated after 12 months.

For a hunter, the trade is clear. Product-vuln cash for a private report is gone. Cash for a merged fix is not. For a maintainer, the trade is worse: the patch still has to be reviewed, and the junk reports that no longer earn a Google ticket can still arrive as pull requests and issues.

Curl Shut the Bounty and the Reports Kept Coming

Google is late to a choice other maintainers already made. Daniel Stenberg, founder and lead of curl, ended that project’s cash bounty on January 31, 2026, after AI-written reports wrecked the valid-hit rate. The curl bug-bounty officially stopped in January following a run that, from April 2019, had produced 87 confirmed vulnerabilities and more than 100,000 USD in payouts.

The main goal with shutting down the bounty is to remove the incentive for people to submit crap and non-well researched reports to us. AI generated or not.

Daniel Stenberg, curl founder and lead developer, in a January mailing

Stenberg wrote that earlier years saw somewhere north of 15% of submissions become confirmed vulnerabilities, and that from 2025 the confirmed-rate fell to below 5%. In the week he described the shutdown, curl took seven HackerOne issues in a sixteen-hour period. Some were real bugs. None was a vulnerability. He counted twenty submissions already in 2026. The blog’s own short label for the move was an attempt to reduce “terror reporting.”

Killing the bounty removes the lottery ticket. It does not remove the reports. Curl’s later public comments described volume that kept climbing even after the cash stopped, with write-ups that were longer and, increasingly, technically careful rather than hallucinated. That is the part Google’s pause does not solve. Invalid automated filings are the stated cause. Valid automated filings at maintainer scale are the next queue, and they still need a human.

$31,337 Still on the Table for Supply Chain

The live OSS VRP reward table now shows a blank product-vulnerability row at every tier. The supply-chain row is the one Google went out of its way to keep. A hunter who can modify main-branch code, steal package-publisher credentials, or break signing keys on an OT0 project can still ask for the top band, which runs to $31,337. Google also still pays $1,000 at OT0 and $500 at OT1 for “other security issues,” the bucket for leaked credentials and similar misses that are not classic product bugs.

WHAT OSS VRP STILL PAYS

Category OT0 Flagship OT1 Important OT2 Standard OT3 Low-priority
Supply-chain compromises $3,133.7 to $31,337 $1,337 to $13,337 $500 to $3,133.7 None
Product vulnerabilities Not accepted Not accepted Not accepted Not accepted
Other security issues $1,000 $500 None None

The panel still sets the final number, and it may pay more for a wide-reaching bug or less for one that needs extra unproven steps. It typically pays once per root cause. A small bonus of about $1,000 can attach to a clever finding or a clean write-up. OT3 projects, the experimental and sample repos, still pay nothing.

Keeping supply chain open is a bet about impact, not about volume. A poisoned build of a flagship library is a different class of failure from a memory bug in a parser. It is also harder to fake with a chatbot, because the hunter has to show an exploit that bypasses the usual “external contributors need a reviewed PR” rule. Google is still willing to buy that demonstration. It is no longer willing to buy a stack of product-bug PDFs.

Tsunami and SCALIBR Were Already on Hold

The Patch Rewards invitation sits next to two sibling programs that Google has already taken off the calendar. Tsunami Patch Rewards, which paid for scanner plugins and fingerprinting work, has been on hold since April 9, 2026, and is not taking new requests. OSV-SCALIBR Patch Rewards, tied to Google’s filesystem scanner for vulnerability detection and software inventory, has been on hold since July 6, 2026. InternetCTF Tsunami rewards were frozen on the same April date as Tsunami itself.

Chrome VRP, Android VRP, Cloud VRP, AI VRP, and the main Google and Alphabet VRP remain listed as live. Those programs cover products with a different intake staff, and they are the “other VRP programs” Google waved at in the PSA. They do not replace a dedicated paid channel for Google’s public GitHub orgs. Researchers who used OSS VRP as the private road into Go or Angular now have a merged-patch bounty, a supply-chain bounty, and a calendar invite for Q1 2027.

Until that update lands, the people who still read unsolicited product bugs in Google open source are the maintainers. The paid private queue that used to sit in front of them is dark, and the reports did not get the same message.

Harry is the editor of Oton Technology, an independent site he owns and edits, covering the part of technology that people actually have to act on. After ten years in journalism, first reporting and then editing, he works from primary material by habit: the advisory rather than the write up of it, the filing rather than the press release, the changelog rather than the launch video. Every figure in an article carries its source and its date, and where a number comes from a vendor or an analyst model rather than a count, he says so plainly instead of letting it stand as established fact. What he leaves out is anything he could not verify himself, which on a beat full of unnamed supply chain claims removes a great deal. That standard applies across all the sections the site publishes for an international audience, from artificial intelligence and security to phones, computers, gaming, crypto and the software businesses depend on. He corrects errors in the open and labels them, because a site that hides its mistakes is asking readers to trust the rest on nothing.

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending