Google Pauses Product Vulnerability Submissions to Its Open Source Bug Bounty: Automated Reports Surge, and "the Vast Majority" Are Invalid

Starting October 1, Google stopped accepting product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP), citing "a significant rise in automated submissions, the vast majority of which are not valid," and committed to an update in Q1 2027. The pause does not affect supply chain reports or reports already submitted; researchers can still submit open-source security patches through the Patch Rewards Program (up to $15,000), or report issues tied to Google Cloud and AI products to the Cloud VRP and AI VRP. OSS VRP launched in August 2022 and paid $100 to $31,337 per vulnerability.

What's paused and what isn't

On October 1, Google's Vulnerability Reward Program posted on X that it is temporarily no longer accepting OSS VRP product vulnerability submissions, because of "a significant rise in automated submissions, the vast majority of which are not valid." The paused category covers design or implementation flaws in Google's open-source software that could affect user data in downstream builds.

What continues is spelled out too: supply chain reports are still accepted, and reports submitted before October 1 will be handled as usual. Researchers can also submit security fixes for open-source projects through the Patch Rewards Program, worth up to $15,000, and open-source issues closely tied to Google Cloud or AI products can go to the Cloud VRP or the AI VRP. Google says it will rework this part of the rules and give an update in Q1 2027, but it has not committed to a reopening date.

Not the first

OSS VRP launched in August 2022, paying $100 to $31,337 per vulnerability. Its code of conduct already banned low-quality submissions and told participants to verify anything automated tools produce, but that clearly wasn't enough. Tom's Hardware reports that Google engineers and open-source maintainers were overwhelmed by invalid reports, some containing content the model simply made up. BleepingComputer notes that the curl project ended its HackerOne bounty in January over AI spam, and Intel dropped cash rewards in mid-September.

What it means

AI has cut the cost of filing a plausible-looking vulnerability report to almost nothing, while maintainers still bear the full cost of checking it, and that breaks the incentives behind bug bounties. In the short term, careful researchers get locked out along with the spammers; in the long term, bounty programs will likely raise the bar: reproducible proof-of-concept requirements, submission rate limits, or reputation before access. Researchers using AI to hunt bugs should treat human verification and runnable reproduction steps as the minimum for any submission.

via: Google VRP post on X, OSS VRP rules page, BleepingComputer report, TechCrunch report