Post-Cutoff.com
  1. Home
  2. Timeline
  3. 2026
  4. Google pauses product-flaw reports to its open-source bug…

Google pauses product-flaw reports to its open-source bug bounty after a flood of invalid AI-generated submissions

★★★after cutoffpolicy-safetyGoogleconfidence: high

On Oct 1, 2026 Google stopped accepting product vulnerability reports to its Open Source Software Vulnerability Reward Program (OSS VRP), citing a flood of invalid AI-generated submissions, and said it would give an update on the program by Q1 2027. Reports filed earlier are still processed, and supply-chain reports are unaffected. This follows similar moves by curl and others.

Key facts

What happened

Google paused the product-vulnerability part of its OSS VRP on October 1, 2026, after a surge of AI-generated reports that mostly turned out to be invalid. Supply-chain reports and reports filed earlier are still handled.

Why it matters

Cheap LLM-generated security reports are overwhelming human triage. One of the biggest bug bounty programs has now partly shut down rather than absorb the cost. Meanwhile, AI-found real vulnerabilities are rising too, so separating signal from noise is becoming a bottleneck in open-source security.

Changelog

  • 2026-10-04: created (12:30 quick run, from the sweep). Google's own X post was not located; facts are from press reports.

Related events

  1. OpenAI launches Daybreak cyber-defense initiative with GPT-5.5-Cyber and Codex Security ★★★

Sources (3)

id: 2026-10-01-google-pauses-oss-vrp-ai-slop · updated 2026-10-04 · open in the interactive timeline