Google pauses open-source bug bounty over AI-generated reports
Google has temporarily stopped accepting new product vulnerability reports through its Open Source Software Vulnerability Reward Program, citing a sharp rise in automated submissions that are mostly invalid. Supply-chain reports and the Patch Rewards Program remain open, with a program redesign promised in Q1 2027.
- New product reports to the OSS VRP paused since October 1, 2026
- Cause is a surge in automated submissions, most of them invalid
- Supply-chain reports and Patch Rewards Program remain open
- Program update promised in the first quarter of 2027
Read next
Security