Google Pauses Open-Source Bug Bounty Program After Flood of Invalid AI-Generated Reports
Google paused new OSS VRP product reports after a flood of mostly invalid AI-generated submissions.
Google stopped accepting new product vulnerability reports in its Open Source Software Vulnerability Reward Program on October 1, 2026, after a sharp rise in automated submissions that mostly failed validation. Supply-chain reports remain eligible, reports filed before the cutoff will still be handled, and some Google Cloud repository issues can go to the separate Cloud VRP. Google said AI-written reports often invent exploit paths, wrong trigger conditions, or unreachable bugs and create a heavy triage burden. It expects to update the program in the first quarter of 2027; flagship OT0 supply-chain rewards still range from $3,133.7 to $31,337.