Google has temporarily stopped accepting new submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP), after what the company describes as a sharp surge in automated reports — the "vast majority" of which turned out to be invalid.
What happened
The OSS VRP covers security flaws across Golang, Angular, Bazel, Protocol Buffers, Fuchsia, and third-party dependencies in repository configurations, GitHub Actions, and access controls. Launched in 2022 with rewards ranging from $100 to $31,337, it has been one of the more prominent open-source bounty programs in the industry.
The pause applies only to new product vulnerability submissions — supply-chain reports and anything already in the queue are unaffected. Researchers can still route findings through Google's Patch Rewards Program (up to $15,000 for high-impact fixes) or the Cloud VRP for Google Cloud's open-source repositories. Google says it is working to "reformat" the OSS VRP's intake process, with more detail expected in the first quarter of 2027, and that nothing submitted before October 1, 2026 is affected by the change.
Why it matters
The scale of what's being paused is notable. Since 2010, Google has awarded more than $81.6 million through its vulnerability reward programs. 2025 alone was a record year — $17.1 million paid to over 700 researchers, a 40% jump from 2024. A program with that much reach and reward is exactly the kind of target automated, low-effort submission tools are built to exploit.
Google isn't acting alone. The curl project shut down its HackerOne bounty in January after being buried in what its maintainer called "AI slop." Intel removed financial rewards from its Intigriti bug bounty program in mid-September. And Microsoft warned back in May that AI tooling would increase "the pace and breadth of vulnerability discovery," raising operational demands across the industry — a prediction borne out last month when Microsoft patched a record 966 flaws, including two actively exploited zero-days.
The underlying problem isn't that AI is finding real bugs faster — it's that a bounty program's value depends on a human reviewer being able to trust the signal in front of them. When automated noise drowns that signal, the economics of the whole model break down, regardless of how many genuine vulnerabilities are still out there.
What to do
- If you operate a bug bounty or vulnerability disclosure program, add automated triage gates — duplicate detection, proof-of-concept validation, submitter reputation scoring — before reports reach a human reviewer.
- Treat review-queue capacity as an operational cost line, not just a researcher-relations issue. AI-generated noise competes directly for the same scarce reviewer time as genuine findings.
- If your organization depends on third-party disclosure pipelines for coverage (Google, curl, or other open-source maintainers), track program changes like this one and make sure internal scanning and code review fill any gap it leaves.
- Expect stricter proof-of-concept and reputation requirements to become standard across major bounty programs as this Q1 2027 Google update — and others like it — roll out.
