Google has paused acceptance of product vulnerability reports under its Open Source Software Vulnerability Rewards Program (OSS VRP) starting October 1, citing an overwhelming volume of AI-generated invalid reports that has worn down both its engineers and open source maintainers. Google's bug bounty team announced the move on its official account, calling it a "temporary" pause and saying it will share next steps for the program before the first quarter of 2027.
OSS VRP covers Google's public code repositories, including widely depended-on projects like Golang, Angular, and Bazel. What's being paused is the program's largest category: product vulnerabilities — code defects, logic errors, and design flaws.
What's still covered
The program isn't shutting down entirely. According to Google, several categories of submissions are unaffected:
- Reports already submitted before October 1 will be processed as usual;
- OSS VRP's supply chain reports — covering compromised build pipelines and tampered packages — continue to be accepted;
- Vulnerabilities affecting repositories tied to Google Cloud products can be redirected to Cloud VRP;
- Google's other bounty and patch reward programs remain unchanged.
Google's stated reason is blunt. Researchers using large language models and automated scanning tools can "mass-produce polished-looking reports," but much of the content is model hallucination, or describes issues that have no real security impact. Engineers end up spending their time disproving false claims instead of fixing real vulnerabilities. Google hasn't disclosed the volume or share of invalid reports behind this decision.
The third move this year
This pause marks the third time this year Google has adjusted its bounty rules in response to AI-generated reports, and each round has been more aggressive than the last.
In March, Google publicly voiced concerns about low-quality AI submissions, responding at the time by adding requirements to the rules and warning submitters. In May, it overhauled the Chrome and Android bounty programs to explicitly favor reports with a reproducible proof of concept (PoC), downgrading submissions without one. OSS VRP also rewrote its own rules during the year in an attempt to filter out low-quality reports — but, judging by the outcome, it didn't work. By October, Google simply stopped accepting them.
Google isn't the first to hit this wall. The curl project ended its own bug bounty program earlier this year, with its maintainer having repeatedly complained publicly about fake AI-generated vulnerability reports; the Internet Bug Bounty, which covers the open source ecosystem, has also paused new submissions due to a surge in volume; and reports suggest maintainers of the Linux networking subsystem have likewise acknowledged a flood of AI-driven patches and reports.
There's an irony here: Google itself uses AI to find vulnerabilities. According to public reporting, Google's AI-powered vulnerability-hunting agent reported 20 real vulnerabilities last year. The same category of tool that produces results in a reviewed, supervised workflow becomes a burden for maintainers when used to mass-farm bounties.
What it means for submitters and maintainers
For independent researchers who rely on bounties for income, the most immediate impact is that one revenue channel has temporarily closed, leaving supply chain reports and Cloud VRP as the remaining outlets. Google's own notice points submitters toward these paths.
For open source maintainers, the fact that a program at Google's scale has chosen to stop accepting reports altogether suggests that tweaking rules and raising the bar alone can no longer keep AI-generated reports out. Other bounty platforms will likely now grapple with whether to mandate PoCs or introduce reputation tiers for submitters. Google's promised update before Q1 2027 will be worth watching — whether it reopens the program fully, reopens it with limits, or folds product vulnerabilities into another program.
Sources: Google Bug Hunters official notice, Google OSS VRP rules page, Hardware Busters, CocoLoop, PBX Science; the scope of the pause and retained channels follow Google's official statement, and bounty amount ranges follow the program's rules page.