Google pauses product bug reports in its open-source reward program
Google says a surge of mostly invalid automated submissions led it to stop taking one class of reports, while other disclosure routes remain open.
A narrower change than a full shutdown
Google stopped accepting new product-vulnerability reports through its Open Source Software Vulnerability Reward Program on October 1, its published rules say. Previously submitted product reports are unaffected. The rules still describe supply-chain compromise reports and direct some issues affecting Google Cloud or AI products to their separate reward programs. Google also points researchers toward patch rewards. This is a pause in one submission category within the open-source program, not a closure of every Google bug bounty.
Why Google says it paused reports
TechCrunch reported the change on October 4 and quoted Google saying there had been a significant rise in automated submissions, the vast majority of which it considered invalid. That is Google’s assessment of the incoming reports; the reviewed sources do not independently count them or show that every AI-assisted report lacks value. Google says it will continue revising this part of the program and provide an update in the first quarter of 2027. Researchers with genuine findings must now use an applicable alternative route or wait for the program’s next decision.