Google has temporarily stopped accepting new vulnerability submissions to its Open Source Software Vulnerability Rewards Program, better known as the OSS VRP. The pause took effect on October 1, 2026, after Google said its reviewers were being buried under a flood of automated, AI-generated bug reports, most of which turned out to be invalid. Google says it will share an update on the program in the first quarter of 2027.
What Google announced
The announcement came through Google’s verified Bug Hunters account, @GoogleVRP, on October 1, 2026. The message was short and unusually blunt: Google said it was temporarily no longer accepting OSS VRP product vulnerability submissions because of “a significant rise in automated submissions, the vast majority of which are not valid.”
The wording matters. Google did not kill the program. It did not slash rewards or change its scope. It simply closed the intake door for one specific category, product vulnerability reports for Google’s open source software, while it figures out how to handle the new reality of AI-assisted submissions.
What is paused, and what is not
To keep it clear, here is what the pause actually covers:
- Paused: new OSS VRP product vulnerability submissions, effective October 1, 2026.
- Still running: OSS VRP supply chain compromise reports, which Google says are not impacted.
- Unaffected: any reports submitted before October 1, 2026. If your report was already in the queue, it will still be processed.
- Still running: Google’s Patch Rewards Program, which pays for improvements to open source security, is separate and untouched.
The program historically paid anywhere from around $500 to $1,000 for lower-priority issues up to roughly $3,100 to $31,300 for top-tier flagship or supply chain compromise findings. Those rewards are not going away for reports already submitted.
Why AI-generated reports overwhelmed the program
Bug bounty programs pay security researchers for finding real flaws. That model breaks down when the cost of submitting a report drops to nearly zero. Anyone can now point an AI coding agent at a large open source codebase, ask it to hunt for vulnerabilities, and submit whatever it produces.
The problem is that AI models are very good at sounding confident about vulnerabilities that do not actually exist. Security engineers call these hallucinated findings. Each one still takes human time to review, reproduce, and reject. When thousands of them arrive at once, they drown out the legitimate reports from human researchers, who then wait longer for their real findings to be reviewed and paid.
This is not just a Google problem. Across the open source world, maintainers have spent the past year complaining about a wave of low-quality, AI-generated security reports. Google’s move is the highest-profile response so far: the first time a major vendor has fully paused intake for a flagship open source bounty program because of it.
The irony is hard to miss. Google’s own AI models, including the Gemini family we covered recently, are part of the wave of tools making automated vulnerability hunting accessible to everyone. The same AI boom that Google has championed is now straining its security review pipeline.
Why this matters for open source security
For everyday users, the short-term impact is minimal. Google’s open source projects are still being maintained, and security fixes will still ship. But the pause sends a warning signal.
Bug bounties are one of the main incentives for independent researchers to audit open source code in their spare time. If reviewers are overwhelmed and payouts slow down, researchers go elsewhere. Fewer eyes on critical open source libraries means vulnerabilities sit undiscovered for longer, and the next big supply chain incident gets closer instead of further away.
There is a broader policy conversation here too. Governments and industry groups are racing to set rules for AI safety, including the White House AI safety accord we covered earlier this month. Google’s pause is a real-world example of how AI agents are changing security work in practice, not just in theory.
What happens next
Google says it will provide an update in Q1 2027. It has not said what the fix looks like, but the realistic options are a redesigned submission process with stricter validation, AI-detection filtering, or a smaller pool of trusted researchers.
Until then, the lesson for anyone interested in bug bounties is clear: quantity has never been the game, and in the age of automated submissions, quality is worth more than ever. The researchers who will do well when the program reopens are the ones who can still show a real, reproducible flaw with a human-written explanation, which is exactly what the automated wave cannot produce.
As for AI users on the free tier, the flood of automated reports is a reminder of how much work free and cheap AI tools can now do on their own. We recently explained the changes coming to Gemini’s free tier, and tools like these are exactly what lowered the barrier to automated bug hunting.
Frequently asked questions
Is Google’s bug bounty program permanently shut down?
No. Google called it a temporary pause on new OSS VRP product vulnerability submissions, effective October 1, 2026, with an update promised in Q1 2027. Reports submitted before October 1 will still be processed and paid.
Why did Google pause the open source bug bounty?
Google said there was a significant rise in automated, AI-generated submissions, and that the vast majority of them were not valid. Reviewing thousands of invalid reports overwhelmed the engineers triaging real vulnerabilities.
Can I still report a supply chain compromise to Google?
Yes. Google said the pause does not impact OSS VRP supply chain reports, and its Patch Rewards Program is also unaffected.
What does this mean for bug bounty hunters?
For now, there is no point submitting new product vulnerability reports to the OSS VRP. Hunters should hold real findings for when the program reopens, or consider other bounty programs. When it does reopen, expect stricter submission requirements designed to filter out automated reports.
When will the program reopen?
Google has only committed to an update in the first quarter of 2027. No reopening date has been announced.
