Google's open-source bug bounty facing a flood of AI-generated vulnerability reports
Image: Google

Google Open-Source Bug Bounty Pauses New Reports After AI Flood

The pause affects new product vulnerability submissions to Google's OSS VRP, while supply-chain reports and earlier submissions remain outside the freeze.

Google's open-source bug bounty has temporarily stopped accepting new product vulnerability submissions through its Open Source Software Vulnerability Reward Program, or OSS VRP. The pause took effect October 1, 2026, after Google said a significant rise in automated submissions had overwhelmed the people responsible for reviewing them.

The important detail is that Google has not shut down the entire OSS VRP. Existing product vulnerability reports are still being handled, supply-chain reports are not covered by the pause, and some vulnerabilities affecting Google Cloud products can be routed through the separate Cloud VRP. Google says it plans to provide an update on the program in the first quarter of 2027.

Why the Google Open-Source Bug Bounty Paused

Google had already warned about the same problem in March. Its OSS VRP team said it had seen a surge in AI-generated reports containing incorrect information or hallucinated explanations of how a vulnerability could be triggered. It also saw reports identifying real coding errors that had little practical security impact because the vulnerable code was not reachable under the project's security model.

Google's earlier response was to raise the evidence bar. Certain memory-corruption reports for its highest-priority open-source projects began requiring exact OSS-Fuzz reproduction steps or a merged patch. Lower-tier projects also lost reward eligibility for some product vulnerabilities. The October pause goes further by stopping new product-vulnerability intake while Google reworks that part of the program.

That distinction matters. The issue is not that AI-assisted security research is useless. Google itself says AI and automation can accelerate vulnerability discovery, while its broader security programs increasingly combine automated tools with human researchers. The problem is the cost of validating large numbers of reports that are not actionable.

What This Means for Security Researchers

For researchers, the immediate change is narrower access to one Google reward channel, not a ban on reporting vulnerabilities to Google. The company's Bug Hunters platform continues to direct researchers toward multiple programs, including Android, Chrome, Cloud, AI, Mobile and other vulnerability reward programs.

The shift also fits a broader change in Google's security strategy. Saganote has covered Google CodeMender's AI vulnerability-finding and fixing agent, as well as Microsoft's MDASH AI vulnerability scanning. Google's own March rules update makes the direction clear: reward evidence of real-world impact and reproducible vulnerabilities rather than lengthy reports alone.

Saganote has also covered AI security testing that reached three real companies, showing the other side of the equation: AI can produce useful security findings when the discovery process is tied to verification and real-world impact.

Google's next stated checkpoint is the first quarter of 2027. That update should reveal whether the company can redesign the OSS VRP around stronger verification without losing the independent researchers who make bug bounty programs useful.


Share this
Previous
Apple Doesn't Promise iPhone 18 Pro Support, But Its History Points to the Early 2030s

Apple Doesn't Promise iPhone 18 Pro Support, But Its History Points to the Early 2030s

Oct 5, 2026

Saganote

About Author

Saganote

Saganote is an independent technology publication covering artificial intelligence, cybersecurity, startups, software, consumer technology, and innovation. Our editorial team researches, writes, and reviews original news, analysis, and explainers to provide accurate, timely, and well-sourced coverage of the technology industry.