Google halts new OSS VRP product-vulnerability reports after flood of invalid AI-generated submissions
Google stopped accepting new paid product-vulnerability reports under its Open Source Software Vulnerability Rewards Program on October 1, 2026, after a surge of mostly invalid AI-generated submissions; supply-chain reporting continues and a program update is…
Google stopped accepting new paid product-vulnerability reports under its Open Source Software Vulnerability Reward Program (OSS VRP) effective October 1, 2026, citing a sharp rise in automated submissions that were mostly invalid and overwhelmed engineers and open-source maintainers. Google said AI-written reports often contained hallucinations, including invented exploit paths, wrong trigger conditions, and unreachable bugs, creating a heavy triage burden. Sources disagree on scope: TechCrunch and Infosecurity Magazine described the open-source bounty as suspended or paused until 2027, while Help Net Security, BleepingComputer, GBHackers, Cyber Security News, SecurityWeek, and The Hacker News limited the stop to new product-vulnerability reports, with supply-chain compromise reports still rewarded, submissions filed before October 1 still processed, and some Google Cloud repository issues still reportable through the separate Cloud VRP. The program, launched in August 2022, covers Google open-source projects including Go, Angular, Flutter, Bazel, and Protocol Buffers; The Hacker News said those projects no longer list product rewards that had ranged from $500 to $7,500 for flagship projects, Infosecurity Magazine cited OSS VRP payouts of $100 to $31,337 by severity, and Cyber Security News said flagship OT0 supply-chain rewards remain $3,133.7 to $31,337. Google directed researchers to the Cloud VRP, Google AI VRP, and the Patch Rewards Program, which BleepingComputer said offers up to $15,000. All sources said a program update is planned for the first quarter of 2027, and The Hacker News noted Google gave no date for resuming product reports. Malwarebytes said the pause is intended to let Google add controls such as proof-of-concept requirements and rate limits. The move fits a broader 2026 trend: curl ended its HackerOne bounty (in early 2026, per Malwarebytes) over AI-slop reports, BleepingComputer said Intel removed Intigriti financial rewards in September, SecurityWeek said Google tightened Chrome and Android bounty rules in May over AI-assisted vulnerability discovery, and CSO Online noted Google had tightened open-source program rules in March to require stronger evidence, reproductions, or patches. CSO Online added analyst warnings that triage volume — reviewers must still confirm affected code exists, attack paths are reachable, and impact is real — can consume engineering capacity and delay confirmed high-risk fixes; it also noted Vercel…
- New paid product-vulnerability reports under OSS VRP stopped effective October 1, 2026.
- Cause: surge of automated, mostly invalid AI-generated submissions, including hallucinated exploit paths, wrong trigger conditions, and unreachable bugs that overwhelmed triage.
- Supply-chain compromise reports remain rewarded; Cyber Security News says flagship OT0 supply-chain rewards still range from $3,133.7 to $31,337.
- Reports filed before October 1, 2026 are unaffected and continue through normal triage.
- OSS VRP launched in August 2022 and covers Google open-source projects including Go, Angular, Flutter, Bazel, and Protocol Buffers.
- Reward figures vary by source: The Hacker News says flagship product rewards had ranged from $500 to $7,500 and are no longer listed; Infosecurity Magazine cites OSS VRP payouts of $100 to $31,337.
- Alternatives remain open: Cloud VRP (for some Google Cloud repository issues), Google AI VRP, and the Patch Rewards Program (up to $15,000, per BleepingComputer).
- Program update promised for Q1 2027; The Hacker News says Google gave no date for resuming product reports.
Coverage timelineoldest first · each row is one article
- · 4d agoGoogle froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
TechCrunch · Security· 58
Google paused its open-source bug bounty until 2027 after a surge of invalid AI-generated reports.
- · 3d agoAI slop submissions force Google to freeze its open-source bug bounty
Help Net Security· 60
Google paused new OSS VRP vulnerability reports after invalid AI-generated submissions overwhelmed reviewers.
- · 3d agoGoogle halts open-source bug bounty program amid AI spam surge
BleepingComputer· 58