Read as article
Google Strips OSS Bug Bounty Reward Table, Sets Q1 2027 Update
By @sharedot · · 6 pages
- Programming
- Bug Bounty
- Open Source
Google removed product-vulnerability payout tables from its OSS bug bounty rules and promised a Q1 2027 update amid ongoing AI slop reports.
The reward table vanished overnight
The pause Google announced on X on October 1 came with a quieter change: the OSS Vulnerability Reward Program rules, edited on its public GitHub copy on September 30, deleted the listed payout ranges for product vulnerabilities — $500 to $7,500 for flagship projects and $101 to $3,133.7 for important ones. The Hacker News reports the same edit added the notice of the stop, which has been in effect since October 1. Google called the halt temporary, blaming 'a significant rise in automated submissions, the vast majority of which are not valid,' and committed to an update in the first quarter of 2027 — with no date for reopening product vulnerability submissions.
What still pays, and where reports can go
Supply chain compromise reports — flaws that could let someone tamper with a project's source code or published packages — keep their listed rewards: $3,133.7 to $31,337 for flagship repos like Go, Angular, Flutter, Bazel and Protocol Buffers, $1,337 to $13,337 for important ones, and $500 to $3,133.7 for standard projects. Per The Hacker News, Google's notice names three alternative routes: the Cloud VRP for some Google Cloud repositories (capped at severity IT3b), the Patch Rewards Program paying $100 to $15,000 for accepted patches, and Google's other VRPs such as the AI VRP. The notice does not say whether unfunded product vulnerability reports will still be accepted.
The AI slop trail behind the pause
This is escalation, not a first step. According to The Hacker News, Google began requiring stronger proof for reports in some tiers in March 2026 — a merged patch counts — after the program team worried about low-quality AI-generated submissions that invented details about how a vulnerability could be triggered. TechSpot reports the human review staff simply cannot keep up with the automated influx, and notes that Linux, Microsoft Edge and other major open-source projects face the same flood, while smaller teams have shut their doors to AI-generated contributions entirely. The Go project added a security-policy section on LLM-generated reports in early September, warning it is just as good at reporting bugs that do not exist as at finding real ones.
Project channels now diverge
The practical fallout is uneven across Google's flagship repos. The Hacker News reports Go takes security reports by email to its own security team, while a security policy in Google's GitHub organization points reporters to g.co › vulnz. Angular's policy, as of October 6, still sends vulnerability reports to Google's Bug Hunters site and names no alternative channel — meaning Angular researchers may have nowhere paid to file. Google's tier list, last updated in mid-September, names 26 flagship and 47 important repositories. With an update promised only in Q1 2027, researchers hunting flaws in Go, Angular and Protocol Buffers face months of uncertainty over which channels survive.