google bug hunters oss vrp discontinuation banner

Since 2022, Google’s Open Source Software Vulnerability Reward Program (OSS VRP) has been the path for outside researchers to get paid for reporting security flaws in the company’s open source code, including projects like Flutter, Angular, Go, and Fuchsia.

With an announcement on X, they have now decided to discontinue the product-facing side of it.

They are calling the change temporary, while supply chain reports remain open and anything submitted before October 1 stays unaffected.

What’s closed, what’s not?

Product vulnerabilities are bugs in the projects themselves, like a failing HTML sanitizer, memory corruption issues in file format parsers, or insecure code examples in documentation.

The updated rules do not limit the change to a specific project tier, as they just won’t be accepting any reports related to this.

Supply chain reports, on the other hand, cover vulnerabilities in how the software is built and shipped. Exposed package manager credentials used to publish build artifacts is one case the rules page lists. It remains unaffected by this change.

There’s also an exception for some Google Cloud repositories. If a bug there affects a Cloud product, Google may still accept the report, but through its Cloud VRP.

Why did it come to this?

Back in March, a post on the Bug Hunters blog from Google engineers said AI-generated reports were flooding the program. Some were serving up hallucinated information, while others were flagging legit coding errors that had little to no impact on the security posture of the targeted project.

Google’s first response was to raise the bar on memory corruption reports for its two top project tiers. Researchers had to either reproduce the bug through an existing OSS-Fuzz fuzz target or point to a patch that maintainers had already merged.

An update to the same post the following month went further. The standard and low-priority tiers, OT2 and OT3, stopped offering rewards or credit for product vulnerabilities and other security issues. The top supply chain reward for OT2 projects also fell to $3,133.70.

Supply chain reports still pay, from $500 on OT2 projects up to $31,337 on flagship ones.

As an alternative, Google points to the Patch Rewards Program, which pays between $100 and $15,000, though only for patches that have stayed in a project for a month without being reverted.

An open question

Google has not said when or in what form product vulnerability reports will return. Their announcement only promises an update in the first quarter of 2027 while they continue reworking that part of the program.

There’s also a loose end. At the time of writing, the OSS VRP page still lists reward ranges for product vulnerabilities, up to $7,500. Though, as you saw earlier, the rules page for it has already been updated, so it shouldn’t be long before this is addressed.


Suggested Read ๐Ÿ“–: cURL gets rid of its bug bounty program due to AI.

Leave a Comment