In response to an increase in invalid automated vulnerability submissions, Google has made a significant change to its Open Source Software Vulnerability Reward Program (OSS VRP). The company announced a temporary halt to product vulnerability submissions within this program, as declared on October 1.
Surge in Invalid Reports
Google has cited a substantial rise in automated reports, the majority of which were deemed invalid, as the primary reason for this pause. This decision affects only product vulnerability submissions, leaving other aspects of the program, such as supply chain reports and pending submissions, unaffected. Reports submitted before October 1, 2026, will still be processed under the previous guidelines.
Alternative Venues for Vulnerability Submissions
Despite the pause on product vulnerabilities, Google continues to accept related submissions through other channels. For Google Cloud products, vulnerabilities may still be reported through the Cloud VRP. Additionally, security researchers are encouraged to utilize the Patch Rewards Program, which rewards efforts to enhance the security of open source projects.
Google has committed to revising and improving the OSS VRP and plans to provide further updates by the first quarter of 2027. This move aims to streamline the process and ensure that valid submissions are efficiently managed.
Background and Future Outlook
The OSS VRP, launched in 2022, compensates researchers for identifying vulnerabilities in Google’s open source projects. This recent adjustment follows similar changes made to Google’s Chrome and Android reward programs earlier this year. The modifications were driven by the increasing use of AI tools in vulnerability discovery, which led to a reduction in standard Chrome payouts and a focus on more challenging vulnerability types for Android.
In a related development, the Internet Bug Bounty (IBB) program, managed by HackerOne, also paused new submissions in March, highlighting the challenges posed by AI-assisted discoveries outpacing the community’s ability to implement fixes. Google’s proactive approach in adjusting its programs reflects an ongoing commitment to maintaining robust security measures, adapting to technological advancements, and supporting the open source community.
