Google has paused new product-vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP), ...
Legitimate vulnerabilities could face delays before they are reviewed and fixed.
Since October 1, 2026, Google has not accepted a single new product vulnerability report for its open-source projects, and has not said when payouts return beyond an update promised for early next ...
Google has paused new submissions to the open-source bug bounty that paid up to $31,337 per flaw in projects like Go and ...
Google is temporarily pausing monetary rewards for capable bug hunters because its human staff can't keep up with the current ...
Overview:  Google paused new product vulnerability submissions to its OSS VRP on October 1, 2026, after a sharp rise in ...
Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded ...
Vulnerabilities in Google's open source projects that are closely linked to Google Cloud or AI products are directed to the Google Cloud Vulnerability Reward Program (Cloud VRP) or the AI ...
Google plans to pay out cash rewards for information on vulnerabilities discovered in any of its open source projects as part of an ongoing effort to improve the security of open source code. The new ...