Google has quietly stopped accepting product vulnerability reports to its Open Source Vulnerability Reward Program (OSS VRP), the bounty track that pays independent security researchers for flaws in the company's open-source projects. The pause took effect on October 1, 2026, and was announced on the program's website and on X; TechCrunch reported it on October 4. Google's explanation was unusually blunt: "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid."
The OSS VRP, launched in 2022 with a top award of $31,337, covers projects such as Bazel, Angular, Fuchsia, Go and TensorFlow. According to Tom's Hardware, Google engineers and open-source maintainers have been buried under thousands of reports that claim critical vulnerabilities but turn out, on inspection, to be ordinary coding errors with no security impact — or outright hallucinations describing flaws that do not exist. Every one of them still has to be read and dismissed by a human.
That asymmetry is the whole story. Generative AI has driven the marginal cost of writing a plausible-looking vulnerability report to effectively zero, while the cost of validating one — reading the code, reproducing the claim, ruling it out — has not moved at all. A submitter can flood the queue in seconds; triage still runs at reading speed. Google did not publish its own submission volumes, but the company says it will "reformat" the program and give an update in the first quarter of 2027.
The freeze is narrower than the headlines suggest. Reports filed before October 1 will still be processed. Supply-chain reports — compromised build pipelines and tampered packages — are unaffected, and for Google Cloud repositories, product vulnerability reports can still come in through the separate Cloud VRP. Google's Patch Rewards Program, which pays for security patches rather than reports, remains open, as does the main Google VRP.
Google is also not alone. Industry roundups compiled around the announcement point to a wider collapse in submission quality across bug bounty programs: curl ended its roughly seven-year bounty in January 2026 after the share of valid reports fell from above 15 percent to under 5 percent; Intel paused its own program — which paid up to $100,000 per flaw — in September 2026; Apple added submission caps and a 30-day cooldown in August 2026; and HackerOne paused the Internet Bug Bounty funding pool in March 2026, ending the Node.js bounty that ran on it. Linux kernel maintainers have separately described being "completely overwhelmed," with per-release CVE counts approaching 2,000, versus roughly 500 in the 6.x era.
The economic logic is uncomfortable for the security industry. AI was trained on open-source code, is pointed at open-source code, and produces reports that consume the time of unpaid open-source volunteers — a genuine tragedy of the commons in which the people least equipped to absorb the cost are the ones paying it. Some programs are already responding with structural fixes: curl reported that after it removed monetary rewards, the valid-report rate recovered to the 15-16 percent range, and reputation-based quotas plus AI-assisted pre-screening are widely expected to become standard.
For researchers, the immediate consequence is straightforward: one well-trodden path to bounty income is closed until at least Q1 2027, and the bar elsewhere is moving from volume to demonstrated, high-impact findings. For Google and every other operator of a bug bounty program, the lesson of the pause is blunter: when report generation is free, validation capacity — human or automated — is the scarcest resource in vulnerability disclosure.
Comments (0)
Log in to join the discussion
Log InNo comments yet