Google has quietly closed the door on a significant portion of its bug bounty program. As of October 1, 2026, the company is no longer accepting product vulnerability reports for its open-source software through its bug bounty channel, a move that affects researchers looking to submit security flaws in the code of projects including Go, Angular, and Protocol Buffers, according to The Hacker News.

What Changed

The shift is narrow but consequential. Google's OSS bug bounty program covered two broad categories: vulnerabilities found in the open-source products themselves, and supply chain compromises affecting those projects. Only the first category is being paused. Reports concerning supply chain compromises are still accepted, and any submissions filed before October 1 will continue to be processed under the old rules.

In practice, this means a researcher who discovers a memory safety flaw, injection issue, or logic bug in a Google-maintained open-source library can no longer submit it through the OSS bug bounty for a reward. They will need to route such findings through the project's own security disclosure process instead.

Why Google Pulled the Plug

The company attributed the decision to a surge in invalid reports, many of which appear to be the product of automated tooling and large language models. Bug bounty programs across the industry have been contending with a rising tide of low-quality, machine-generated submissions that consume triage resources without delivering actionable security value. Google's OSS program, which covers a sprawling portfolio of widely used projects, was particularly exposed to this problem.

This is not an isolated phenomenon. Security teams at multiple major vendors have reported that AI-assisted report generation has made it trivially easy to produce plausible-looking vulnerability write-ups at scale. The reports often lack reproducibility, reference nonexistent code paths, or simply restate known issues. For program operators, every invalid submission carries a real cost in engineer time, and the volume can overwhelm the legitimate findings buried within.

The Broader Tension in Bug Bounties

Google's move highlights a structural tension that has been building for years. Bug bounty programs were designed to incentivize independent researchers to find and responsibly disclose real vulnerabilities. That model depends on a reasonable signal-to-noise ratio. When the noise floor rises sharply, the economics of the program change: payouts stay the same, but triage and validation costs climb.

Some organizations have responded by tightening submission requirements, demanding proof-of-concept exploits, or requiring reproduction steps before a report is even triaged. Others, like Google in this case, have narrowed the scope of what they will accept through the bounty channel altogether.

The decision also raises questions about where OSS vulnerability reporting goes from here. Google's open-source projects typically have their own security policies and disclosure processes, and those remain available. But the bug bounty acted as a centralized, incentivized entry point. Removing it may reduce the volume of reports reaching Google's security teams, but it could also reduce the number of legitimate findings that would have been submitted for a reward.

What This Means for Researchers

For security researchers who focus on open-source software, the practical implications are immediate:

  • Product vulnerabilities in Go, Angular, Protocol Buffers, and similar projects are no longer eligible for OSS bug bounty rewards through Google's program.
  • Supply chain compromise reports remain in scope and can still be submitted for reward consideration.
  • Pre-October 1 submissions will be handled under the rules in place at the time they were filed.
  • Alternative disclosure paths exist through individual project security policies, but these typically do not carry monetary rewards.

Researchers who have built workflows around Google's OSS bounty may need to reassess which projects are worth their time. The incentive structure has shifted, and the calculus for spending hours on a deep code audit of a Google-maintained library is now different.

The AI Report Problem Isn't Going Away

Google's decision is best understood as a defensive measure against a problem the entire industry is grappling with. As generative AI tools become more capable, the cost of producing a superficially credible vulnerability report approaches zero. The cost of validating one, however, remains high.

Programs that fail to adapt will either drown in invalid reports or be forced to close scope, as Google has done here. The likely long-term outcome is a bifurcation: bounty programs will demand increasingly rigorous evidence, and automated triage systems will be deployed to filter submissions before they reach human analysts. Neither solution is free, and both change the relationship between researchers and the vendors that pay them.

For now, Google's OSS bug bounty remains open for supply chain reports, and the company has not indicated whether the pause on product vulnerabilities is temporary or permanent. Researchers and program watchers will be looking for signals about whether other vendors follow suit.