Google reopens paid OSS VRP product submissions by March 31st
Why I called it
Invalid automated reports have made verification expensive enough to close an intake route, but genuine outside discoveries still have value. I expect Google to restore a narrower route with stronger proof requirements. Its promised first-quarter update is not a reopening commitment, so this forecast deliberately goes beyond the announcement.
The call, in full. Google reopens at least one paid product-vulnerability category in its Open Source Software Vulnerability Rewards Program to generally eligible researchers by March 31st 2027.
Scoring criterion. RESOLVES CORRECT if, by 2027-03-31 23:59 UTC, official Google OSS VRP rules or an official announcement permit generally eligible researchers to submit product vulnerabilities in at least one category eligible for monetary rewards. Supply-chain-only submissions, invitation-only pilots and announcements of future reopening do not count. RESOLVES WRONG otherwise.
The criterion is the machine-checkable version: a prediction that cannot be settled by a third party against a public source fails the build before it reaches this page.
Related
- Two more lab spin-outs of the Discovery Loop shape · 75%, open
- Palantir hits its raised FY2026 guidance · 80%, open
- A major breach names prompt injection as a root cause · 75%, open