Google Pauses Open Source Bug Bounty Program as AI-Generated Reports Pile Up
Key Takeaways
- •Google halted new product vulnerability submissions to its OSS VRP effective October 1, 2026, because a surge of AI-generated reports included hallucinated vulnerabilities and most submissions in the recent wave proved invalid.
- •The suspension is partial: reports filed before October 1, supply chain reports, and certain Cloud-related submissions remain unaffected and can proceed through existing channels such as the Cloud VRP.
- •Google had already raised evidence requirements in March 2026 and adjusted its Android and Chrome reward programs during 2026, making the OSS VRP pause its most aggressive step so far.
- •The Internet Bug Bounty program, Intel, and Linux kernel maintainers have faced similar waves of questionable generative AI-driven reports, and some have responded with pauses or adjustments of their own.
- •Google expects to publish a formal update on revised submission processes in Q1 2027, which will indicate whether the bounty model can be fixed with better rules or requires an entirely different structure.

Google has suspended new product vulnerability submissions to its Open Source Software Vulnerability Reward Program, citing an influx of low-quality, AI-generated bug reports. The pause took effect on October 1, 2026, and applies to the program known as the OSS VRP. Such programs pay independent researchers for disclosing genuine security flaws, making the quality of each submission a direct cost to the reviewers on the other side.
Why Google Is Pausing the Program
According to the company, the suspension stems from a wave of automated reports produced with AI tools. Those submissions have been landing on Google's security engineers and on the maintainers of open source projects.
Google said many of the reports contained hallucinations—plausible-sounding vulnerabilities that an AI tool generates but that do not actually exist—while others described issues with negligible real-world impact. Most of the submissions in the recent surge proved invalid.
The volume poses a structural problem for bug bounty operations, which depend on manual triage: a human must read each report, attempt to reproduce the issue, and determine whether it represents a genuine vulnerability.
What Remains Open
The move is a partial pause rather than a full shutdown. Under the new cutoff:
- Reports filed before October 1 will continue to be processed without interruption.
- Supply chain reports are not affected by the suspension.
- Certain Cloud-related submissions can still be routed through Google's Cloud VRP.
Google is also directing researchers toward its other active reward programs during the pause, specifically naming its Patch Rewards program as an option.
The company said it plans to revise how submissions work, with a formal update on those reforms expected in the first quarter of 2027.
A Problem Google Has Already Tried to Fix
The suspension is not Google's first attempt to manage the issue. In March 2026, the company adjusted its VRP criteria to slow the flow of low-quality reports, raising the bar on the evidence researchers were required to provide. Google also made changes to its reward programs for Android and Chrome during 2026. The OSS VRP suspension, however, is the most aggressive step taken so far.
Google is far from alone. The Internet Bug Bounty program has run into the same problem, as have Intel and the maintainers of the Linux kernel, all of which have faced rising volumes of questionable reports driven by generative AI. Some of those programs have responded with pauses and adjustments of their own.
Why the Bounty Model Is Under Strain
Open source projects feel the burden most acutely. Many are maintained by small teams or volunteers with no spare capacity to debunk hallucinated vulnerabilities, and Google cited the strain on these maintainers directly in explaining the pause. That burden has broader significance because many of these projects serve as building blocks for much of the software in use across the industry.
What This Means for Researchers
For security researchers, the immediate effect is a narrower set of avenues for rewards from Google's open source work. Those who find legitimate flaws in open source products will need to turn to other Google VRPs or the Patch Rewards program.
The Q1 2027 update is the next milestone to watch. It will indicate whether Google believes the bounty model can be repaired with better rules, or whether open source security rewards require an entirely different structure.