Google pauses open-source bug bounty submissions after flood of AI-generated reports
The freeze limits new filings in one program while Google says pre-existing and supply-chain reports can still be handled.
Google has paused new vulnerability submissions to its Open Source Software Vulnerability Reward Program because automated AI reports flooded the program with mostly invalid findings, making it harder for engineers and maintainers to focus on real issues. The freeze took effect on October 1 and does not apply to reports filed before that date, nor to OSS VRP supply-chain reports. Google said researchers can look at its other bounty programs, and it plans to provide an update in the first quarter of 2027. The move reflects a wider problem in security programs as AI-generated bug reports increase the review burden for maintainers.
Why it matters
For open-source maintainers and Google engineers, the problem is not a lack of reports but too many that do not hold up. By pausing new submissions in this program, Google is trying to reduce the review load and keep attention on issues that are real and actionable, while directing researchers to other bounty paths until it gives an update in the first quarter of 2027.
Keep or strike?
Does this story matter, or is it hype? Mark it before you see what everyone else did.
Sources
- Tom's Hardware
- TechCrunch