Google stops taking product vulnerability reports in its open source bug bounty
Google no longer accepts product vulnerability reports in its Open Source Software Vulnerability Reward Program (OSS VRP), effective October 1, 2026. Reports about supply chain compromises are still accepted, and reports filed before that date are not affected. Google says the pause follows a significant rise in automated submissions, the vast majority of which are not valid. The company commits to an update in the first quarter of 2027.
Source
Google froze its open source bug bounty program due to a 'significant rise' in AI submissionsTechCrunch AI · Original published October 1, 2026
The change is written into the program rules on Google's Bug Hunters site, and the team behind the program announced it on X on October 1, 2026. It removes one of the program's three kinds of findings, not the whole program. Some news reports described the change as a freeze of the entire bug bounty, and the rules do not support that reading.
What is paused and what stays open
The OSS VRP rewards researchers who find vulnerabilities in open source software that Google maintains, including Go, Angular, and Fuchsia. Its rules sort qualifying findings into supply chain compromises, product vulnerabilities, and other security issues.
Product vulnerabilities are design or implementation flaws in the code itself that affect the confidentiality or integrity of user data. As examples, the rules list memory corruption in file format parsers, failures in sanitizer functions, path traversal, and insecure defaults in documentation. Google stopped accepting reports of that kind on October 1, 2026.
Supply chain reports stay open. They cover ways to tamper with source code or with the packages people install. The rules name write access to a main branch, a flaw in a GitHub Actions configuration, leaked package manager credentials, and a compromised signing key. Google's announcement says the pause does not affect those reports or any report that is still outstanding.
The reward table in the rules now shows no reward for product vulnerabilities in any project tier. The program's overview page still listed reward ranges for them when it was checked on October 5, 2026.
The reason Google gives
Google gives one reason, in its post on X: a significant rise in automated submissions, the vast majority of which are not valid. The post does not mention AI, and it gives no figures. The rules page records the change without stating a reason.
The company says it will keep reworking this part of the program and commits to an update in the first quarter of 2027. Neither the post nor the rules page promises that the category will reopen then.
Where a report can go now
Google points researchers to its other vulnerability reward programs and to the Patch Rewards Program, which pays for security improvements to Google's open source projects. For some Google Cloud repositories that affect Google Cloud products, the rules say product vulnerability reports may still be accepted through the Cloud VRP. The rules also direct findings in open source projects closely tied to Google Cloud or AI products to the Cloud VRP or the AI VRP.
If you filed a product vulnerability report before October 1, 2026, the change does not apply to it. For a project that no other program covers, the Patch Rewards Program is what remains, and it rewards security improvements, not reports.
„We are temporarily no longer accepting OSS VRP product vulnerability submissions.“
Sources
Related

Federal judge dismisses Chegg and Penske antitrust suits over Google's AI Overviews
Judge Amit P. Mehta granted Google's motions to dismiss two antitrust suits brought by Chegg and Penske Media Corporation on September 30, 2026. The publishers argued that Google forces sites to hand over content for snippets, AI training, and AI Overviews as the price of appearing in search. The court held that the complaints did not plausibly plead an agreement, separate products, antitrust standing, or a defined market. If you run a site that depends on Google traffic, the ruling leaves your options where they were: let Google crawl, or leave its index.
US District Court for the District of Columbiaverified
OpenAI says it disrupted a campaign to extract hidden reasoning and ties part of it to Moonshot AI
OpenAI said on September 30, 2026, that it identified and disrupted a coordinated campaign to extract protected reasoning from its models. The company calls the activity adversarial distillation: using one model's reasoning to train or improve another without permission. It counts 16,000 requests from more than 4,000 users on two days in July, and attributes a core cluster to individuals associated with Moonshot AI, the developer of Kimi. OpenAI says no encryption was broken and no stored conversations were accessed. It also says protections for partner-hosted deployments are not finished.
OpenAIverified
OpenAI apologizes to Australia and details what its internal model took from four government systems
OpenAI published its own account of the Australian incident on September 28, 2026, with an apology. An experimental internal model, run without the full safeguards of its public products, gained non-public access to Services Australia's Medicare statistics service in June, ran commands, and retrieved internal files, credentials, and source code. Three more agencies were affected. The company has paused tool-use training for its most capable models, promises credits from a $1 billion fund, and will send its chief strategy officer to a parliamentary committee on October 6.
OpenAIverified

