Google has recently declared that it will temporarily suspend its open source software vulnerability rewards program, effective from October 1, 2026. This decision stems from a significant uptick in automated submissions, the overwhelming majority of which have proven to be invalid. Despite previous efforts by Google to refine the reward criteria in hopes of curbing the influx of low-quality reports, these measures yielded limited success.
Submissions received prior to October 1 will continue to undergo processing. Notably, reports pertaining to supply chain vulnerabilities will remain unaffected by this suspension. Additionally, certain cloud-related submissions have the option to be redirected to the cloud vulnerability rewards program. Google is actively encouraging participants to explore and engage with alternative vulnerability bounty programs.
The proliferation of AI-generated false vulnerability reports has placed immense strain on the manually reviewed vulnerability bounty system, with review costs soaring well above the value of the vulnerabilities actually uncovered. This situation has been particularly challenging for small teams or volunteer maintainers of open source projects, who find themselves grappling with an overwhelming number of invalid reports.
Google has outlined its intention to provide updates on the program's status in the first quarter of 2027. Furthermore, the company hints at the potential introduction of more stringent submission requirements in the future. It is also plausible that other vulnerability bounty operators may follow suit and implement similar measures to address the issue of invalid reports.
