> ## Content Index
> Fetch the complete content index at: https://itsfoss.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Google Has Shut Down Part of its Open Source Bounty Program
- URL: https://itsfoss.com/news/google-oss-vrp-product-reports-closed/
- Published: 2026-10-07T10:46:45.000Z
- Updated: 2026-10-07T10:46:45.000Z
- Description: Submitting product vulnerability reports is no longer possible. You can thank AI for that.
- Author: Sourav Rudra
- Tags: News

Since 2022, Google's Open Source Software Vulnerability Reward Program (OSS VRP) has been the path for outside researchers to get paid for reporting security flaws in the company's open source code, including projects like *Flutter*, *Angular*, *Go,* and *Fuchsia*.

With an announcement on [X](https://x.com/GoogleVRP/status/2105689195180179605?ref=itsfoss.com), they have now decided to discontinue the product-facing side of it.

They are calling the change temporary, while supply chain reports remain open and anything submitted before October 1 stays unaffected.

## What's closed, what's not?

> 📢 PSA for open-source bug hunters  
>  
> We are temporarily no longer accepting OSS VRP product vulnerability submissions. This does not impact OSS VRP supply chain reports, or any outstanding reports. As an alternative, we encourage you to find impact across our other VRP programs…
> 
> — Google VRP (Google Bug Hunters) (@GoogleVRP) [October 1, 2026](https://x.com/GoogleVRP/status/2105689195180179605?ref%5Fsrc=twsrc%5Etfw&ref=itsfoss.com)

Product vulnerabilities are bugs in the projects themselves, like a failing HTML sanitizer, memory corruption issues in file format parsers, or insecure code examples in documentation.

The [updated rules](https://bughunters.google.com/about/rules/open-source/google-open-source-software-vulnerability-reward-program-rules?ref=itsfoss.com#product-vulnerabilities) do not limit the change to a specific project tier, as they just won't be accepting any reports related to this.

Supply chain reports, on the other hand, cover vulnerabilities in how the software is built and shipped. Exposed package manager credentials used to publish build artifacts is one case the rules page lists. It remains unaffected by this change.

There's also an exception for some Google Cloud repositories. If a bug there affects a Cloud product, Google may still accept the report, but through its [Cloud VRP](https://bughunters.google.com/about/rules/google-friends/cloud-vulnerability-reward-program-rules?ref=itsfoss.com).

## Why did it come to this?

Back in March, a post on [the Bug Hunters blog](https://bughunters.google.com/blog/ossvrp-rule-updates-2026?ref=itsfoss.com) from Google engineers said AI-generated reports were flooding the program. Some were serving up hallucinated information, while others were flagging legit coding errors that had little to no impact on the security posture of the targeted project.

Google's first response was to raise the bar on memory corruption reports for its two top [project tiers](https://github.com/google/bughunters/tree/main/oss-repository-tier?ref=itsfoss.com). Researchers had to either reproduce the bug through an existing [OSS-Fuzz](https://github.com/google/oss-fuzz?ref=itsfoss.com) fuzz target or point to a patch that maintainers had already merged.

An update to the same post the following month went further. The standard and low-priority tiers, *OT2* and *OT3*, stopped offering rewards or credit for product vulnerabilities and other security issues. The top supply chain reward for *OT2* projects also fell to $3,133.70.

Supply chain reports still pay, from $500 on OT2 projects up to $31,337 on flagship ones.

As an alternative, Google points to the [Patch Rewards Program](https://bughunters.google.com/about/rules/open-source/patch-rewards-program-rules?ref=itsfoss.com), which **pays between $100 and $15,000**, though only for patches that have stayed in a project for a month without being reverted.

## An open question

Google has not said when or in what form product vulnerability reports will return. Their announcement only promises an update in the first quarter of 2027 while they continue reworking that part of the program.

There's also a loose end. At the time of writing, the [OSS VRP page](https://bughunters.google.com/open-source-security?ref=itsfoss.com) still lists reward ranges for product vulnerabilities, up to $7,500\. Though, as you saw earlier, the rules page for it has already been updated, so it shouldn't be long before this is addressed.

---

**Suggested Read 📖:** cURL [gets rid of its bug bounty program](https://itsfoss.com/news/curl-closes-bug-bounty-program/) due to AI.

[cURL Gets Rid of Its Bug Bounty Program Over AI Slop OverrunDaniel Stenberg says the inflow of AI slop has become unsustainable for the curl security team to handle.![](https://itsfoss.com/content/images/icon/android-chrome-512x512-5d41197a-60a8-4658-a93e-5221136d2dfa.png)It's FOSSSourav Rudra![](https://itsfoss.com/content/images/thumbnail/curl-bug-bounty-program-discontinued-0b3991f9-dfd6-4b63-b881-b9f82e3de151.png)](https://itsfoss.com/news/curl-closes-bug-bounty-program/)