Google pauses product vulnerability submissions to OSS bug bounty program
Google has temporarily stopped accepting product vulnerability submissions under its Open Source Software Vulnerability Rewards Program, citing a surge of automated, mostly invalid AI-generated reports. Supply chain reports and previously submitted reports are unaffected, and researchers can still use the Patch Rewards Program or Cloud VRP. Google says it will rework the OSS VRP and provide an update in Q1 2027.
GoKawiil's interpretation of the reporting above, not reported fact.
The pause illustrates a broader strain AI-generated content is placing on systems built for human-scale review, forcing companies to reconsider how they verify submissions. It suggests bug bounty programs across the industry may need new filtering mechanisms to distinguish genuine findings from automated noise, which could slow legitimate research in the interim.
- Google has suspended OSS VRP product vulnerability submissions due to AI-spam flooding.
- Supply chain reports, outstanding submissions, and other VRP programs remain active.
- Google plans to update the program's structure, with details expected in Q1 2027.
Source: bleepingcomputer.com, 2026-10-05
Published there as: “Google halts open-source bug bounty program amid AI spam surge”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.