Close Menu
NCIJ Network NCIJ Network
    What's Hot

    How Much More Trump Trouble Can Indonesia’s Prabowo Take?

    October 6, 2026

    Did Buzz Aldrin say, ‘The moon is not what you think’?

    October 6, 2026

    ‘Ghost particles’ from space telescope wins 2026 Nobel Prize in Physics

    October 6, 2026
    Facebook X (Twitter) Instagram
    Trending
    • How Much More Trump Trouble Can Indonesia’s Prabowo Take?
    • Did Buzz Aldrin say, ‘The moon is not what you think’?
    • ‘Ghost particles’ from space telescope wins 2026 Nobel Prize in Physics
    • Spain PM pins hopes on housing crisis to help win snap election
    • The Internet Runs on Cats and Porn. It’s About to Get Cattier and Pornier
    • Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports
    • Solana Debuts Institutional Settlement Standard With J.P. Morgan Input
    • What Our Reporter Learned From Gambling on DraftKings for 10 Weeks — ProPublica
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, October 6
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 6, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalOct 06, 2026Vulnerability / Open Source

    Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software.

    The change, in effect since October 1, means researchers can no longer submit security flaws in the code of projects such as Go, Angular, and Protocol Buffers there for a reward. Reports about supply chain compromises are still accepted, and reports filed before October 1 are not affected.

    Google called the stop temporary in a post on X on October 1 and said it was due to “a significant rise in automated submissions, the vast majority of which are not valid.”

    The post gave no figures. It did not say whether the submissions were produced with AI tools.

    The rules of the program, called the Open Source Software Vulnerability Reward Program (OSS VRP), now carry a notice of the stop. It commits Google to an update in the first quarter of 2027 while it reworks this part of the program.

    Neither the post nor the notice gives a date for accepting product vulnerability reports again.

    Under the rules, a product vulnerability is a design or implementation flaw in Google’s open source software. It must substantially affect the confidentiality or integrity of user data in software built with that code. Examples include memory corruption in file format parsers and path traversal.

    Cybersecurity

    The program sorts projects into four tiers based on their sensitivity. Only the top two, called flagship and important, had rewards listed for product vulnerabilities.

    The same change that added the notice removed those listed amounts: $500 to $7,500 for flagship projects and $101 to $3,133.7 for important ones. It was published to Google’s public GitHub copy of the rules on September 30, a day before the X post.

    Google’s list of tiered repositories, last updated in mid-September, names 26 flagship repositories and 47 important ones. The flagship tier includes Go, Angular, Flutter, Bazel, and Protocol Buffers.

    Supply chain compromises, which are flaws that could let someone tamper with a project’s source code or published packages, keep their listed rewards. So do other security issues, such as leaked credentials that give write access.

    Category Flagship Important Standard
    Supply chain compromises $3,133.7 to $31,337 $1,337 to $13,337 $500 to $3,133.7
    Product vulnerabilities None (was $500 to $7,500) None (was $101 to $3,133.7) None
    Other security issues $1,000 $500 None

    The fourth tier, for low-priority projects, has no listed rewards.

    Where Reports Can Go Now

    Google’s notice names three routes for researchers:

    • Cloud VRP: Product vulnerability reports may still be accepted for some Google Cloud repositories that affect Google Cloud products, but the notice does not name them. Under the Cloud VRP rules, a flaw in an open source repository maintained by Google Cloud that affects Cloud products is rated at most IT3b. That is the tier for acquisitions and lower-priority products, and the cap applies unless Google’s product list says otherwise.
    • Patch rewards: The Patch Rewards Program pays $100 to $15,000 for security patches to the projects it covers, not for vulnerability reports. The project’s maintainers must accept a patch and remain in place for one month before it can be submitted. A patch that fixes only a single vulnerability is reviewed on a case-by-case basis.
    • Other reward programs: Google asks researchers to check whether a flaw affects something covered by one of its other reward programs and to submit it there. The OSS VRP rules also encourage reporting flaws in projects closely tied to Google Cloud or AI products to the Cloud VRP or the AI VRP.

    The notice does not say whether Google will still take product vulnerability reports without a reward.

    Some project policies point to other channels. Go takes security reports by email to its own security team. A security policy in Google’s GitHub organization sends reporters to Google’s vulnerability reporting address, g.co/vulnz.

    Cybersecurity

    Angular’s security policy, as of October 6, says Angular is part of the OSS VRP, sends vulnerability reports to Google’s Bug Hunters site, and names no other channel.

    Earlier Limits on Low-Quality Reports

    Google launched the OSS VRP in August 2022. In March 2026, it began requiring stronger proof for reports in some tiers to filter out low-quality ones. A patch already merged into the project is one accepted form of proof.

    InfoWorld reported at the time that the program’s team was concerned about the low quality of some AI-generated submissions, many of which included invented details about how a vulnerability could be triggered.

    Separately, the Go project added a section on reports generated by large language models (LLMs) to its security policy in early September. It asks reporters not to send such reports without reviewing and filtering them first.

    The policy says LLMs are good at finding real security bugs and just as good at reporting ones that do not exist. Reporters who forward large amounts of unfiltered LLM output will not be credited for their findings.

    Automated Bounty Bug Google Invalid OSS pauses product reports Rewards surge
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Engineer sentenced for locking over 3,000 devices on employer network

    Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

    ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

    Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

    Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

    South Korea probes bank breaches amid suspected AI-powered attacks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    How Much More Trump Trouble Can Indonesia’s Prabowo Take?

    October 6, 2026

    Did Buzz Aldrin say, ‘The moon is not what you think’?

    October 6, 2026

    ‘Ghost particles’ from space telescope wins 2026 Nobel Prize in Physics

    October 6, 2026

    Spain PM pins hopes on housing crisis to help win snap election

    October 6, 2026
    Latest Posts

    What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience

    August 9, 2026

    Britain is paying the price for failing to invest in its young people | Richard Partington

    August 9, 2026

    A Democratic Socialist Spreads the Word, Even in Hostile Territory

    August 9, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    How Much More Trump Trouble Can Indonesia’s Prabowo Take?

    October 6, 2026

    Did Buzz Aldrin say, ‘The moon is not what you think’?

    October 6, 2026

    ‘Ghost particles’ from space telescope wins 2026 Nobel Prize in Physics

    October 6, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.