AI NewsOpen sourceAnnouncement
Google paused its open-source bug bounty for product vulnerabilities on October 1, blaming AI submissions
Google's Open Source Vulnerability Rewards Program stopped taking product vulnerability submissions on October 1, 2026, with the team citing a rise in automated submissions it says are mostly invalid, and promising an update by Q1 2027.
Why it mattersA security researcher who files AI-assisted reports to Google's open-source bounty has nowhere to send them until next year, and open-source maintainers inside Google get back the hours those reports were taking.
A paid bug bounty program that security researchers have run reports through for Google's open-source code is closed to new product vulnerability submissions, and the reason given is the volume of reports written with AI help. Google's Open Source Software Vulnerability Rewards Program announced the pause on October 1, 2026, and said it will share an update in the first quarter of 2027.
The announcement is a short post from the GoogleVRP account on X: a public service announcement that the team is no longer accepting OSS VRP product vulnerability submissions, that supply chain reports and outstanding reports are not affected, and that researchers should look at Google's other VRP programs in the meantime. The program's rules page carries the same text. TechCrunch and Tom's Hardware both quoted Google's own line that "this pause is due to a significant rise in automated submissions, the vast majority of which are not valid."
What is still running
The pause is only on product vulnerability reports: the OSS VRP's supply chain stream, which pays for discoveries about how packages reach users, remains open. Reports that were already in the queue when the pause began are still being worked on. Google said in the Tom's Hardware report that it may still accept product vulnerability reports via its Cloud VRP for some Google Cloud repositories, so a bug in a Cloud product's source tree still has a route.
Why this happened
Tom's Hardware, in Etiido Uko's October 3 piece, writes that Google engineers and open-source maintainers "were reportedly being overwhelmed by thousands of poorly written reports that claimed to find bugs but were actually completely invalid or unexploitable hallucinations." The practical cost named is time: hours spent reading an AI-generated report that produces no fix, instead of hours spent on a real one.
The move follows similar pressure elsewhere. Tom's Hardware notes that Linux maintainers said last month they were "completely overwhelmed" by CVE finds, and that the Linux kernel has reached about 2,000 vulnerabilities per release as AI-powered bug hunters probe its 40 million lines of code. Intel suspended its own bug bounty program, which paid up to $100,000 per flaw, earlier this year without naming AI reports as the cause.
For a security researcher whose income depends on OSS VRP payouts, the practical change is three months with no new product submissions accepted and no money paid for a product vulnerability found between now and the update Google has promised. For a team using LLMs to triage dependency vulnerabilities before filing them, the message is that filing matters less than reading: a report that cannot be reproduced in a few minutes is now the problem, not the fix. Supply chain remains the one place inside Google's open-source bounty where a researcher can still earn money today.
Source
This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.
Get AI News in your inbox
New developer tools, model and agent releases, and how teams are actually using them to release software. Short, and only when there is something worth reading.


