Analysis of Google’s OSS VRP partial pause (October 1, 2026).

TL;DR: Google stopped accepting new product bug reports in OSS VRP — vulnerabilities in Google open-source code (Go, Angular, etc.) are not paid through OSS VRP right now. Supply-chain attacks (build poisoning, artifact tampering) still qualify. Outstanding pre-pause reports continue processing.

Headlines claiming the entire bounty program is frozen until 2027 are incorrect. Only product vulnerability submission channel is paused.

Cloud VRP may still accept product vulnerabilities for some Google Cloud-linked repositories (“may” — not all repos).

AI VRP (launched October 2025) covers Google/Alphabet AI product security — distinct from standard OSS code bugs. Normal Go vulnerabilities are not AI VRP scope.

Parallel industry trend: cURL suspended its bug bounty in January 2026 due to AI-generated low-quality reports. Linux community reported ending support for older network drivers amid false AI bug report influx.

Operational impact: maintainers overwhelmed validating hallucinated or unexploitable AI-generated findings; engineering time diverted from real vulnerability remediation.