In brief

Google has paused the main part of its Open Source Software Vulnerability Reward Program. Since October 1, it no longer accepts reports of security flaws in the code of its open-source projects. Google blames a sharp rise in automated reports, most of which were not valid.

New to this? Read it in simple words
  • Google pays people who find security flaws in its open-source code.
  • Since October 1, it no longer takes the main kind of these reports.
  • Google says most of the automated reports it got were not valid.
  • It promised an update in the first quarter of 2027.
Words to know
Bug bounty
A program that pays outsiders for finding and reporting security flaws.
Open source
Software whose code anyone can read, use and change.
Hallucination
When an AI system states something false as if it were true.

What changed

Google said it is “temporarily no longer accepting OSS VRP product vulnerability submissions”. These are reports of flaws in the code of Google’s public projects.

Reports about attacks on the software supply chain are still accepted, and so are reports sent before October 1. Some flaws that affect Google Cloud products can still go to the Cloud program, GIGAZINE reports.

Google pointed researchers to its other reward programs, and to its Patch Rewards Program, which pays for security fixes.

Sources134

PROGRAM STATUS 01
Too many reports, too few real.

From Google’s post and rules page, as quoted by TechCrunch and GIGAZINE.

Why

“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” Google said in its post.

Google gave no numbers, and its own words say “automated”, not AI. Tom’s Hardware reported that Google engineers and open-source maintainers were overwhelmed by reports that were invalid or contained hallucinations, TechCrunch notes.

Google promised “an update” in the first quarter of 2027. It did not say whether this part of the program will reopen then.

Sources23

Not the first

Other bug bounty programs have hit the same problem this year, GIGAZINE reports. The team behind curl, a widely used networking tool, ended its bug bounty in January, after repeated low-quality reports made with AI.

HackerOne’s Internet Bug Bounty stopped taking new submissions in March. In August, Apple limited how many reports a researcher can send, according to GIGAZINE.

Sources3

Sources

Every fact in this story comes from the sources below. Open them to check our work.

  1. 1
    Primary source · October 1, 2026Google Open Source Software Vulnerability Reward Program Rules Google Bug Hunters
  2. 2
  3. 3
  4. 4
    Research · October 5, 2026Google Pauses OSS VRP Vulnerability Search Over AI Reports The Cyber Express
How we checked this story

Google’s post gives the reason but no figures. Google says “automated”; that the reports were made with AI is how the outlets read it.

Mood: 5 out of 10 · A little bad news

Google has stopped paying for reports of flaws in its open-source code, a small possible risk to security, with no harm reported. How we rate the mood