IT Home, October 4: Google has announced that, starting October 1, 2026, the Open Source Software Vulnerability Reward Program (OSS VRP) will no longer accept vulnerability reports for products. This policy change does not affect product vulnerabilities submitted before October 1, 2026.
However, for certain Google Cloud code repositories that may impact Google Cloud products, Google may still receive reports through the Cloud VRP if they involve product vulnerabilities.
OSS VRP is a professional security bounty program established by Google to incentivize independent security researchers to identify and responsibly disclose security vulnerabilities across Google's entire open-source ecosystem.
According to Tom's Hardware, insiders reveal that Google engineers and open-source code maintainers have been overwhelmed by thousands of low-quality reports claiming to have discovered critical vulnerabilities—only to find, upon deeper investigation, that all were AI-generated “hallucinations,” entirely invalid and non-exploitable.
The maintenance team had to expend significant effort verifying these fake codes, severely limiting the time available to fix critical real-world vulnerabilities. This was the direct reason Google ultimately terminated the program.
IT Home learned that Google officially stated it will continue to restructure and optimize the relevant mechanisms of OSS VRP, with plans to announce the latest progress in the first quarter of 2027.
