Google has temporarily halted product vulnerability submissions for its Open Source Software Vulnerability Reward Program (OSS VRP) following a surge in automated, low-quality filings. The tech giant cited a significant increase in machine-generated reports, the vast majority of which proved to be invalid or completely false.
The operational freeze took effect on October 1, 2026, and is expected to remain in place while Google restructures its intake process. Internal security teams and repository maintainers will use the hiatus to redesign submission criteria and filtering mechanisms, with an official progress update promised for the first quarter of 2027.
Google Temporarily Suspends OSS VRP Product Bug Submissions
Google launched the OSS VRP in August 2022 to incentivize ethical hackers and independent security researchers to audit its vast open-source portfolio. The program offered financial payouts ranging from $100 up to $31,337 for severe flaws discovered in flagship projects such as Golang, Angular, Bazel, Protocol Buffers, and the Fuchsia operating system. However, the rise of accessible large language models and automated vulnerability scanners has created an unsustainable triage load for Google engineers.
In a statement posted to social media platform X, the Google Bug Hunters team announced the immediate suspension of standard product vulnerability reports. "PSA for open-source bug hunters. We are temporarily no longer accepting OSS VRP product vulnerability submissions," the team confirmed. Addressing the underlying cause, the post stated, "Why is this happening? This pause is due to a significant rise in automated submissions, the vast majority of which are not valid".
Overwhelming Volume of AI-Generated False Reports
The rapid proliferation of automated bug-hunting tools has dramatically lowered the barrier to entry for bug bounty hunters. While automated analysis can help identify real logic flaws, non-technical users increasingly rely on generative models that output speculative findings, hallucinated vulnerabilities, and non-reproducible proof-of-concept scripts. Security researchers refer to this flood of low-value, machine-written disclosures as AI slop.
Reviewing these filings consumes substantial engineering hours. Triage teams must manually inspect code, configure test environments, and verify reports regardless of quality. When thousands of reports arrive with convincing prose but zero technical substance, human verification quickly becomes a bottleneck. Similar incidents have impacted other technology initiatives, including recent shifts where Intel suspended its paid bug bounty program on third-party platforms to pivot toward revised disclosure models.
Scope and Exemptions of the Bug Bounty Freeze
Google outlined clear boundaries regarding what remains open during the pause. Outstanding reports logged prior to October 1, 2026, will continue to move through the standard evaluation pipeline. Security researchers with existing claims do not need to resubmit their findings.
Furthermore, the freeze applies specifically to core open-source product vulnerabilities. Supply chain disclosures under the OSS VRP, such as misconfigured GitHub Actions, compromised dependency trees, and access control oversights, remain active. Security researchers identifying flaws in third-party integrations or CI/CD pipelines can still file reports under existing guidelines.
Supply Chain Vulnerabilities and Cloud VRP Status
Google also clarified that vulnerabilities affecting open-source repositories tied directly to cloud infrastructure can be rerouted. Researchers discovering defects that directly impact enterprise services are encouraged to submit via the Google Cloud VRP or the dedicated AI VRP. Additionally, researchers who develop functional fixes for known bugs can participate in the Google Patch Rewards Program, which offers up to $15,000 for high-impact open-source security patches.
This targeted approach ensures that critical cloud architecture remains defended while engineers isolate the product bug submission forms. The operational shift mirrors broader industry efforts to manage autonomous systems, similar to how Nvidia introduced its open agent safety platform to monitor and constrain automated software workflows.
Future Outlook for Automated Bug Hunting and Security Programs
Google is not the first major organization forced to reckon with automated submissions. Software maintainers across the Linux kernel project, cURL, and various open-source communities have reported escalating friction over AI-generated Common Vulnerabilities and Exposures (CVE) requests. When tools produce plausible-sounding reports without validating exploitability, maintainers bear the full cost of debunking them.
Industry analysts expect Google to introduce stricter acceptance criteria when the program resumes in 2027. Potential changes include mandatory functional proof-of-concept builds, automated pre-screening checks, identity verification, or rate limits on submissions per account. Similar friction between rapid AI deployment and safety controls has appeared in model development, as seen when OpenAI halted a model release following alignment testing concerns.
While generative tools promise to accelerate vulnerability discovery, unvalidated output presents significant operational hurdles for security teams. Google's pause highlights the urgent need for robust intake frameworks that can separate genuine security disclosures from automated noise.