
Google Open Source Software Vulnerability Reward Program
Google pays up to $31,337 for supply chain compromises in its open source projects. Product vulnerability reports are paused since October 1, 2026.
The Google Open Source Software Vulnerability Reward Program pays security researchers who find and report vulnerabilities in open source software released by Google. It covers the latest versions of code in the public repositories of Google owned GitHub organizations and some repositories hosted on other platforms.
The program changed on October 1, 2026. From that date Google no longer accepts product vulnerabilities, such as memory corruption in parsers or path traversal bugs. Google says the rise in automated submissions, most of them not valid, led to the pause. Reports sent before October 1 are still processed. For some Google Cloud repositories, product bugs can still go to the Cloud VRP. Google says it will give an update in Q1 2027.
Supply chain compromises remain the main focus. These are bugs that let someone change code on main branches, take over build and release systems, leak package manager credentials or steal signing keys. Rewards depend on the project tier: $3,133.7 to $31,337 for flagship projects, $1,337 to $13,337 for important projects and $500 to $3,133.7 for standard projects. Other security issues pay $1,000 or $500. The reward panel can pay more for unusually clever or severe findings.
To count, a supply chain bug must work without a maintainer first approving the pull request. If it only triggers after approval, it is treated as insider risk and gets credit, not money. Projects in the lowest tier, such as archived or research repositories, are not paid.
Reports go through the Google Bug Hunters vulnerability form. Pick OSS VRP as the bug location and give the repository URL. Google asks for a buildable proof of concept, steps to reproduce, the affected version and an attack scenario. Google also points researchers to its Patch Rewards Program, which pays for security improvements to its open source projects.
Quick answers
How much does it pay?
Supply chain compromises: $3,133.7 - $31,337 (OT0 flagship projects). It is paid as prizes to the winning entries.
When is the deadline?
There is no fixed deadline. Applications are reviewed as they arrive.
Who can apply?
Security researchers who report supply chain compromises or other security issues in open source software released by Google. Product vulnerabilities are no longer accepted since October 1, 2026. Rewards cannot go to people or entities on sanctions lists, in sanctioned territories, or in Russia or Belarus. Applicants from anywhere in the world can enter, unless the eligibility rules say otherwise.
How do I apply?
Through the official page at bughunters.google.com. The link is at the top of this page.
Are product vulnerabilities still rewarded?
No. Since October 1, 2026 Google no longer accepts product vulnerabilities in this program. Reports sent before that date are still handled, and Google says it will give an update in Q1 2027.
Are bugs in third party dependencies in scope?
Yes, if you show that the bug can be triggered in Google open source software, and you report it at least 30 days after the upstream fix.