Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports
BLUF
Google suspended its open source bug bounty program to combat overwhelming volumes of invalid automated submissions.
NEWS
The tech giant temporarily halted acceptance of vulnerability reports through the OSS VRP following a surge in low-quality, automated findings. This decision affects researchers submitting bugs related to open source software products within Google's ecosystem. The pause aims to filter out noise and restore the program's integrity before resuming operations.
Why I Care
Security researchers lose a critical revenue stream and reporting channel for open source flaws, potentially slowing down vulnerability disclosure. Google risks delayed patching of open source dependencies if valid reports are stalled during the suspension. The broader open source community may face reduced incentives for responsible disclosure until the program stabilizes.
Next Steps
Researchers should pause OSS VRP submissions and monitor official Google security blogs for reopening announcements. Organizations relying on Google's open source tools should increase internal monitoring since external reporting is temporarily limited. Program administrators must implement stricter automation filters before resuming the bounty program.
Source: Security Week ·