AI & ML 4 min read

Google Stopped Paying for One Kind of Open-Source Bug Report After a Flood of Invalid Ones

Since 1 October, Google's reward programme no longer pays for flaws in the code itself, blaming automated submissions. Reports about tampering with builds and packages are still accepted.

Maya Lin
Digital Platforms Analyst
Published 5 Oct 2026, 12:22 PM (SGT)
Share:
Lines of source code on a dark editor screen Lines of source code on a dark editor screen Photo by Harold Vasquez on Pexels
Advertisement

5 OCT 2026 — Google has stopped paying for one kind of bug report in its open-source software, and it says automated submissions are the reason. From 1 October its Open Source Software Vulnerability Reward Program no longer accepts reports of product vulnerabilities, the flaws in the code itself. Reports about how that code is built and published are still accepted.

"This pause is due to a significant rise in automated submissions, the vast majority of which are not valid," the company's Vulnerability Reward Program account posted on 1 October. It promised an update in the first quarter of 2027.

What Google stopped accepting

The programme pays outside researchers for flaws in open-source software that Google publishes. Its rules page splits reports into two classes, and only one of them is paused.

Product vulnerabilities are the paused class. The rules list memory corruption in file format parsers or network protocol code, sanitiser functions that fail, path traversal, and insecure defaults or code samples in a project's documentation. Some Google Cloud repository reports may still be accepted through the separate Cloud programme, and the rules point researchers to Google's other reward programmes or its Patch Rewards Program in the meantime.

Reports already submitted are not affected.

1 OctDate the programme stopped taking product vulnerability reports
Q1 2027When Google says it will give an update
2 classesProduct flaws, now paused, and supply-chain flaws, still accepted
Not givenHow many automated reports Google received, or what share were invalid

What still pays

Supply-chain reports remain open. These cover weaknesses that would let an attacker tamper with Google's open-source code or the packages built from it, such as pushing code to a main branch, exploiting a misconfigured build pipeline, finding leaked credentials for a package registry, or compromising a signing key.

The split matters because the two classes differ in how easily they can be faked. A supply-chain report has to show the attack working: the rules require researchers to demonstrate a way around the requirement that outside contributions are approved first, or the report is treated as an insider risk and earns only credit.

A bar that was already high

Product reports already had a high bar. On Google's two highest project tiers, a memory corruption report needed exact reproduction steps on OSS-Fuzz, its continuous fuzzing service, or a fix already merged into the project. Lower-tier product vulnerabilities paid nothing.

Advertisement

Even with those rules, Google received enough invalid reports to stop the category. It has not said how many reports it received, how many were judged automated, or how it told them apart.

Not quite a freeze

TechCrunch reported on 4 October that Google had frozen the programme. Google's own wording is narrower. The programme is still running, and the paused category is the one where a plausible-looking report is cheapest to produce and most expensive to check.

Reviewers carry that cost. A report that turns out not to exist eats time and fixes nothing. Chrome shows the opposite pattern. Google patched 1,072 security bugs there in June, more than in the previous two years combined, and more findings meant more fixes. In the open-source programme, Google says, most of what arrived was not valid.

What researchers can do now

For now, a researcher holding a real flaw in a Google open-source project has three routes. If it fits the supply-chain rules, report it there. If it affects a Google product, try one of the company's other reward programmes. Otherwise, submit a fix through the Patch Rewards Program. Google has not said whether the product category will return in its old form.

Advertisement
Maya Lin
Digital Platforms Analyst

Maya Lin covers SaaS platforms, workflow automation, creator tools, and productivity software for RECATOOLS.

View author profile → · Editorial policy

About this byline Maya Lin is a RECATOOLS editorial persona used for platform and productivity coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement