Google pauses open‑source product‑vulnerability bounty after AI‑generated report surge
Google stopped accepting new product‑vulnerability submissions to its Open Source Software Vulnerability Reward Program on 1 October 2026, citing a flood of invalid AI‑generated reports that overwhelmed maintainers.

On 1 October 2026 Google announced a temporary halt to new product‑vulnerability submissions under its Open Source Software Vulnerability Reward Program (OSS VRP). The company said it would issue a detailed update by the first quarter of 2027, but the pause remains in effect for the specific product‑vulnerability stream, not for the entire suite of Google‑run bounty programs.
What the pause covers and what it does not
The suspension applies solely to the product‑vulnerability category of the OSS VRP. Other Google bounty tracks, such as the Cloud Vulnerability Reward Program, continue to accept reports, and OSS supply‑chain submissions are also untouched. Vulnerabilities reported before the 1 October cutoff remain in scope, and certain flaws in Google Cloud repositories that affect Cloud products can still be pursued through the separate Cloud VRP.
Google’s internal analysis linked the pause to a “significant increase in automated and AI‑generated submissions, the vast majority of which it described as invalid.” The surge overwhelmed open‑source maintainers, who found themselves spending valuable time reproducing and rejecting reports that described hallucinated, unexploitable or otherwise non‑existent flaws rather than fixing verified security issues.
Why AI‑generated noise has become a problem
Lowering the cost of scanning and report generation has democratized vulnerability research, enabling more researchers to discover real defects. However, the same reduction in effort also removed a natural barrier that previously filtered out low‑quality submissions. Automated tools can now produce thousands of synthetic reports with minimal human oversight, inflating the volume of noise that program administrators must triage.
- Automated scripts generate reports at scale
- Large‑language models fabricate plausible but false code paths
- Researchers can submit without manual verification
- Maintainers must allocate time to reproduce and reject each report
Open‑source maintainers, many of whom are volunteers, reported that the influx of invalid reports diverted resources away from genuine security work. The time spent on reproducing hallucinated flaws not only delayed patch development but also increased burnout among community contributors.
Google’s response and future plans
Google clarified that the pause is a temporary measure while it reworks the affected part of the OSS VRP. The company has not yet published replacement validation rules, but it emphasized that the program is not being shut down permanently. Instead, Google aims to introduce stricter criteria for accepting submissions, likely requiring reproducible evidence, verified impact and a human review step before a report is entered into the bounty pipeline.
TechCrunch and Tom’s Hardware linked the decision to a broader challenge faced by Linux and other open‑source ecosystems, where maintainers are increasingly swamped by low‑quality bug reports. Both publications reported the same timeline and rationale, but any additional claims about other programs are attributed solely to those outlets.
For security teams that rely on external vulnerability disclosures, the pause serves as a reminder to enforce internal vetting processes. Requiring reproducible evidence, clear impact statements and a manual review before filing a ticket can help filter out AI‑generated noise and protect analysts from chasing phantom threats.
The situation also highlights the need for better coordination between bounty platforms and open‑source projects. Clear guidelines on what constitutes a valid report, combined with automated pre‑screening that flags likely hallucinations, could reduce the burden on maintainers while preserving the benefits of a thriving bug‑bounty ecosystem.
For anglophone organizations that participate in open‑source security programs, the pause means they must adjust their vulnerability‑management workflows. Teams should anticipate a longer validation window for product‑vulnerability reports submitted to Google’s OSS VRP, prioritize evidence‑rich submissions, and consider alternative channels—such as the Cloud VRP or direct coordination with project maintainers—for critical findings. In practice, this translates to a temporary slowdown in receiving bounty incentives for certain open‑source bugs, but it also offers an opportunity to focus on higher‑quality disclosures that can be acted upon more swiftly.
Sources
- Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissionsTechCrunch · October 4, 2026
- Google freezes open-source bug bounty program amid flood of invalid AI slop submissionsTom's Hardware · October 4, 2026



