Overview

Google Open Source Software Vulnerability Rewards Program (OSS VRP) pays security researchers for finding vulnerabilities in Google’s open-source projects (Go, Angular, etc.) and supply-chain attacks against Google OSS artifacts.

Recent Developments

  • 2026-10-01: Product vulnerability submissions paused due to surge in automated invalid AI-generated reports (2026-10-04-google-vrp-official-x-post)
  • Still active: supply-chain reports, pre-Oct-1 outstanding submissions, Patch Rewards Program
  • Cloud VRP: may accept some product bugs for Google Cloud-linked repos
  • Update promised Q1 2027 — not guaranteed reopening date
  • Parallel: curl suspended bounty Jan 2026; Linux driver maintenance affected by false AI reports

Warning

Headlines overstating “entire program frozen until 2027” are incorrect. Only the product-vulnerability submission channel is paused.

Sources