Google pauses product-flaw reports to its open-source bug bounty after a flood of invalid AI-generated submissions
On Oct 1, 2026 Google stopped accepting product vulnerability reports to its Open Source Software Vulnerability Reward Program (OSS VRP), citing a flood of invalid AI-generated submissions, and said it would give an update on the program by Q1 2027. Reports filed earlier are still processed, and supply-chain reports are unaffected. This follows similar moves by curl and others.
Key facts
- Effective Oct 1, 2026, announced the same day on X; reports filed before Oct 1 are still processed (Hardware Busters, Tom's Hardware)
- Supply-chain reports (compromised build pipelines, tampered packages) remain in scope; some Google Cloud-related repos can route product bugs through the Cloud VRP
- Reason: LLM-generated reports with confident severity ratings and proofs of concept that usually do not work, which maintainers must still reproduce and close
- Update on the program's future promised by Q1 2027; the OSS VRP launched in 2022 with rewards of $100 to $31,337
- Context (Hardware Busters): curl ended its bug bounty over AI-written reports; Linux networking maintainers say they are swamped by AI-driven patches and reports; Intel's bug bounty is listed as suspended
What happened
Google paused the product-vulnerability part of its OSS VRP on October 1, 2026, after a surge of AI-generated reports that mostly turned out to be invalid. Supply-chain reports and reports filed earlier are still handled.
Why it matters
Cheap LLM-generated security reports are overwhelming human triage. One of the biggest bug bounty programs has now partly shut down rather than absorb the cost. Meanwhile, AI-found real vulnerabilities are rising too, so separating signal from noise is becoming a bottleneck in open-source security.
Changelog
- 2026-10-04: created (12:30 quick run, from the sweep). Google's own X post was not located; facts are from press reports.
Related events
Sources (3)
- pressTom's Hardware: Google freezes open-source bug bounty program amid flood of invalid AI slop submissions
- pressHardware Busters: Google pauses its open-source bug bounty for product flaws as AI slop buries maintainers
- officialGoogle Bug Hunters: OSS VRP rules
id: 2026-10-01-google-pauses-oss-vrp-ai-slop · updated 2026-10-04 · open in the interactive timeline