Anime, manga, and games, with a take · A Yukimedia publication

← all stories other 1 sources · 1d ago ·

Google Halts Open Source Bug Bounty Submissions After Surge in Automated Reports

A program built to pay humans for finding real flaws is now spending its time filtering machine-generated noise, and the same pressure has already pushed cURL and HackerOne to change how they take reports.

Reporting from 1 source: GIGAZINE.

Google Halts Open Source Bug Bounty Submissions After Surge in Automated Reports

Google stopped accepting product vulnerability reports for its Open Source Software Vulnerability Reward Program as of October 1, 2026. The company cited a significant rise in automated submissions, most of them invalid. Supply chain reports and outstanding reports are unaffected. Google says it will reformat the program and give an update in Q1 2027. Some Google Cloud repositories still take reports through Google Cloud VRP.

Product vulnerability reports for the Google OSS VRP closed on October 1, 2026. The rules page now says the program is no longer accepting them. Reports tied to some Google Cloud repositories can still go through Google Cloud VRP, and supply chain reports continue as before.

Google attributes the pause to automated submissions that are mostly invalid or unexploitable. Engineers and maintainers end up verifying code instead of fixing it. The company says it will reformat this part of the program and post an update in Q1 2027.

Synthesized by Yomimono from the 1 cited source below, including Japanese-language reporting where cited, then editorially reviewed before publishing.

Sources