Google Pauses Its Open-Source Bug Bounty After a Flood of AI Bug Reports
On October 1, 2026, Google stopped accepting new product vulnerability reports to its Open Source Software Vulnerability Reward Program (OSS VRP), citing a significant rise in automated submissions, the vast majority of which are not valid. Supply chain reports and reports already filed are unaffected, and Google promises an update in Q1 2027.

Google hits pause on OSS VRP product reports
On October 1, 2026, the Google VRP team announced on X that it is temporarily no longer accepting OSS VRP product vulnerability submissions. The change is reflected in the Google Open Source Software Vulnerability Reward Program rules on Google Bug Hunters.
This page is the long-form briefing behind the BSH Technologies Instagram carousel.
Why Google did it
Google's own explanation is short: "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid." According to Tom's Hardware, Google engineers and open-source maintainers were reportedly overwhelmed by thousands of poorly written reports that claimed to find bugs but were invalid or unexploitable hallucinations, and spent their time validating code instead of fixing real vulnerabilities.
What is paused and what still works
- Paused: new OSS VRP product vulnerability reports (code defects, logic flaws or design bugs in Google's public repositories).
- Still accepted: OSS VRP supply chain reports.
- Still processed: outstanding reports submitted before the pause.
- Alternative route: for some Google Cloud repos that impact Google Cloud products, product issues may still be reported through the Cloud VRP.
- Other options: Google encourages researchers to find impact across its other VRP programs or pursue the Patch Rewards Program.
How long will it last?
Google says it will "continue to reformat and work on this aspect of the OSS VRP" and commits to giving an update in Q1 2027. That is a promise of an update, not a published reopen date. TechCrunch describes the program as paused until next year.
Part of a wider pattern
- Linux: Tom's Hardware reports that Linux maintainers said they were "completely overwhelmed" after AI-powered bug hunters pushed the kernel to a record 2,000 vulnerabilities per release.
- Intel: Intel also suspended its bug bounty program, which paid up to $100,000 per flaw. Intel did not officially confirm AI-generated reports as the reason.
- The economics flipped: LLMs and automated scripts have nearly eliminated the cost of producing a report, while the cost of validating one still lands on human maintainers.
What bug hunters and teams should do now
- Reproduce before you file. A working proof of concept beats a model-written narrative every time.
- Route correctly. Supply chain issues still go to OSS VRP; product issues may fit another Google VRP or the Cloud VRP for some Cloud repos.
- Expect a higher bar. Programs that stay open are likely to tighten triage for AI-assisted reports.
- Maintainers: budget for triage, require reproducible evidence, and make low-effort reports cheap to close.
Primary sources
- Google Bug Hunters: Google Open Source Software Vulnerability Reward Program Rules
- Google VRP on X: PSA for open-source bug hunters (Oct 1, 2026)
- TechCrunch: Google froze its open source bug bounty program due to a 'significant rise' in AI submissions (Oct 4, 2026)
- Tom's Hardware: Google freezes open-source bug bounty program amid flood of invalid AI slop submissions (Oct 3, 2026)
How BSH can help
At BSH Technologies we help teams use AI in security work without drowning in noise: triage pipelines that demand reproducible evidence, AI-assisted code review with human sign-off, and vulnerability disclosure processes that scale. If your team is fielding a flood of AI-generated reports, our Thrissur engineers can turn this briefing into a triage playbook.
Frequently asked questions
What did Google pause?
On October 1, 2026 Google stopped accepting new product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP).
Why did Google pause OSS VRP product reports?
Google cited a significant rise in automated submissions, the vast majority of which are not valid.
Is the whole Google open-source bug bounty closed?
No. OSS VRP supply chain reports and outstanding reports are not affected, some Google Cloud repo issues may go through the Cloud VRP, and Google promises an update in Q1 2027.
From the blog
View all postsApple Tightens macOS Full Disk Access as AI Agents Rise
On October 2, 2026, Apple said macOS Full Disk Access will require very explicit user action. The company warns that some apps use the backup-era permission in ways that can expose files, mail, messages, and browsing history — risks that grow as autonomous AI agents become more capable.
Cloudflare Clef: Open-Weight Decision Models on Workers AI
On October 1, 2026, Cloudflare released Clef and Clef-flash — open-weight decision models on Workers AI under Apache 2.0. Bounded typed choices instead of prose, a vision encoder, 64k context, vendor-reported latency wins over Jev, and a price critics noticed.