Google Freezes OSS Bug Bounty Reports After AI Submission Flood
Google has stopped accepting new product vulnerability reports in its OSS VRP after invalid automated submissions swamped reviewers, while older reports and some Cloud VRP routes remain open.

Google has paused a core route for product vulnerability reports in its Open Source Software Vulnerability Reward Program after invalid AI-generated submissions began consuming reviewer time, Help Net Security reported.
The change took effect on October 1, 2026, when the OSS VRP rules page said Google was no longer accepting product vulnerabilities submitted to that program.
The pause does not close the entire open-source security channel, but it removes one category of bounty intake while the company reworks how those reports are handled.
The affected program covers flaws in Google-released open-source software, including projects such as Go, Angular and Protocol Buffers.
Since its 2022 launch, the OSS VRP has paid researchers who privately report eligible security issues in that code, repository settings and supply-chain components.
Google tied the freeze to the review burden created by automated submissions.
In an official X post, the company said the pause followed a significant rise in automated reports and that most of them were not valid.
The result was a triage problem for the engineers and open-source maintainers who have to separate genuine vulnerabilities from low-quality AI-assisted claims.
Reports submitted before October 1 remain outside the freeze.
Some Google Cloud repositories that affect Cloud products may also still receive product vulnerability reports through the company's Cloud VRP, leaving researchers with a separate route when the affected code falls under that scope.
The immediate workaround is narrower than the previous OSS VRP product-vulnerability path.
Researchers are being directed to other vulnerability reward programs or to Google's Patch Rewards Program, which pays for security improvements to the company's open-source projects.
The reward table now lists no product-vulnerability amounts across the four OSS VRP project tiers, from OT0 for flagship projects to OT3 for low-priority ones.
The pause functions as a control on one intake path rather than a finding about any specific Google project.
Its response logic is procedural: stop new product-vulnerability reports in the affected OSS VRP category, keep pre-October 1 submissions in the queue, leave some Cloud VRP reporting available for Cloud-impacting repositories, and push other work toward separate reward channels.
The move shows how AI-assisted vulnerability reporting is shifting work from discovery to validation.
A generated report can look like a security lead while still lacking the proof, scope or exploitability needed for a bounty program, forcing maintainers to spend time on triage rather than fixes.
Google says it will continue to reformat this part of the OSS VRP and plans to provide an update in the first quarter of 2027.
Until then, product vulnerability submissions for the paused open-source channel remain closed unless they qualify under another Google reward program.




















