Google pauses OSS bug bounty over AI-generated reports
Google has suspended the product vulnerability part of its open-source bug bounty. The company says a surge of automated, mostly invalid submissions overwhelmed the people who have to read them.
The change affects the Open Source Software Vulnerability Reward Program (OSS VRP). Since October 1, 2026, the program no longer accepts product vulnerability reports. The program's rules page now says that "as of October 1, 2026, we are no longer accepting product vulnerabilities submitted to the OSS VRP."
Google explained the decision in a post on X: "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid."
What the OSS VRP covers
Google launched the OSS VRP in 2022. It is the company's bug bounty for the open-source software it publishes, including Go, Angular and Protocol Buffers. Security researchers who find flaws in that code and report them privately can receive a payout. The program also covers repository settings and supply chain components.
On product vulnerabilities, the scope is broad. According to the program rules, "any design or implementation issue in Google OSS that causes a product vulnerability substantially affecting the confidentiality or integrity of user data in software builds using Google OSS is also in scope for the program."
Not every report is judged the same way. Whether a submission is accepted depends on the project's tier and on the subcategory of the vulnerability. The program sorts projects into four tiers, from OT0 (Flagship) down to OT3 (Low-priority). The reward table now shows no amounts for product vulnerabilities in any of the four tiers.
What happens to pending and new reports
The pause does not apply retroactively. Reports submitted before October 1 are still handled.
Researchers who find product vulnerabilities in Google's open-source code now have a few options:
- submit the finding to another Google VRP program
- use the Patch Rewards Program, which pays for security improvements to Google's open-source projects
- for some Google Cloud repositories that affect Cloud products, report through the Cloud VRP, which may still accept them
Google did not give an end date for the pause. "We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027," the company said.
Months of complaints
The decision follows months of complaints from open-source maintainers and bug bounty operators about a flood of low-quality vulnerability reports produced with AI help. Help Net Security reported on these complaints in May.
Google says the burden falls on two groups: its own engineers and the open-source maintainers who review incoming reports. Each submission has to be read, reproduced and assessed. That work costs time whether or not the report turns out to be real.
Our Take
This is one of the clearest signs yet that AI-generated "slop" has gone from a nuisance to an operational problem. A company with Google's resources has decided that, for now, running a bug bounty for product flaws costs more than it returns. Smaller projects without dedicated triage teams are likely under even more pressure.
The pause comes as AI pushes vulnerability research in both directions. We have recently covered how vulnerability disclosures have doubled as AI speeds up exploitation. Google itself has promoted tools such as Gemini 4 Argon for finding and fixing flaws. The same technology that can help skilled researchers also makes it cheap to flood maintainers with plausible-looking but worthless reports.
For legitimate researchers, the immediate effect is the loss of a paid channel for product bugs in projects like Go and Angular. It is still unclear whether that will push some valid findings away from private disclosure. The pause also leaves a supply chain question open: Google's open-source code is built into many products, so it matters where real flaws in it get reported in the meantime.
The Q1 2027 update is the next thing to watch. It will be worth seeing whether Google adds stricter submission requirements, such as working proof-of-concept code, reputation thresholds or limits on automated reports. It is also worth watching whether other bug bounty programs follow with pauses of their own, or whether they can find ways to filter out the noise without shutting the door on genuine research.
