Overview
Google Open Source Software Vulnerability Rewards Program (OSS VRP) pays security researchers for finding vulnerabilities in Google’s open-source projects (Go, Angular, etc.) and supply-chain attacks against Google OSS artifacts.
Recent Developments
- 2026-10-01: Product vulnerability submissions paused due to surge in automated invalid AI-generated reports (2026-10-04-google-vrp-official-x-post)
- Still active: supply-chain reports, pre-Oct-1 outstanding submissions, Patch Rewards Program
- Cloud VRP: may accept some product bugs for Google Cloud-linked repos
- Update promised Q1 2027 — not guaranteed reopening date
- Parallel: curl suspended bounty Jan 2026; Linux driver maintenance affected by false AI reports
Warning
Headlines overstating “entire program frozen until 2027” are incorrect. Only the product-vulnerability submission channel is paused.