Google has paused the main part of its Open Source Software Vulnerability Reward Program. Since October 1, it no longer accepts reports of security flaws in the code of its open-source projects. Google blames a sharp rise in automated reports, most of which were not valid.
New to this? Read it in simple words
- Google pays people who find security flaws in its open-source code.
- Since October 1, it no longer takes the main kind of these reports.
- Google says most of the automated reports it got were not valid.
- It promised an update in the first quarter of 2027.
- Bug bounty
- A program that pays outsiders for finding and reporting security flaws.
- Open source
- Software whose code anyone can read, use and change.
- Hallucination
- When an AI system states something false as if it were true.
What changed
Google said it is “temporarily no longer accepting OSS VRP product vulnerability submissions”. These are reports of flaws in the code of Google’s public projects.
Reports about attacks on the software supply chain are still accepted, and so are reports sent before October 1. Some flaws that affect Google Cloud products can still go to the Cloud program, GIGAZINE reports.
Google pointed researchers to its other reward programs, and to its Patch Rewards Program, which pays for security fixes.
From Google’s post and rules page, as quoted by TechCrunch and GIGAZINE.
Why
“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” Google said in its post.
Google gave no numbers, and its own words say “automated”, not AI. Tom’s Hardware reported that Google engineers and open-source maintainers were overwhelmed by reports that were invalid or contained hallucinations, TechCrunch notes.
Google promised “an update” in the first quarter of 2027. It did not say whether this part of the program will reopen then.
Not the first
Other bug bounty programs have hit the same problem this year, GIGAZINE reports. The team behind curl, a widely used networking tool, ended its bug bounty in January, after repeated low-quality reports made with AI.
HackerOne’s Internet Bug Bounty stopped taking new submissions in March. In August, Apple limited how many reports a researcher can send, according to GIGAZINE.
Sources3
Sources
Every fact in this story comes from the sources below. Open them to check our work.
- 1Primary source · October 1, 2026Google Open Source Software Vulnerability Reward Program Rules Google Bug Hunters
- 2Research · October 4, 2026Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions TechCrunch
- 3Research · October 5, 2026Google temporarily suspends bug bounty program due to a surge in AI-generated bug reports GIGAZINE
- 4Research · October 5, 2026Google Pauses OSS VRP Vulnerability Search Over AI Reports The Cyber Express
Google’s post gives the reason but no figures. Google says “automated”; that the reports were made with AI is how the outlets read it.
Google has stopped paying for reports of flaws in its open-source code, a small possible risk to security, with no harm reported. How we rate the mood