Google has temporarily paused its open source software bug bounty program after seeing a significant increase in automated vulnerability submissions, most of which were found to be invalid.
The company’s Open Source Software Vulnerability Rewards Program (OSS VRP) rewards security researchers who discover and responsibly report vulnerabilities in Google’s open source projects. However, Google said the growing number of automated submissions has placed additional pressure on engineers and open source maintainers.
Google announced that the program was paused on October 1 and said it plans to provide an update during the first quarter of 2027. The company attributed the decision to a “significant rise in automated submissions,” adding that the “vast majority” of these reports were not valid.
The issue highlights a growing challenge for bug bounty programs as security researchers increasingly use artificial intelligence to analyze code and generate vulnerability reports. While AI tools can help researchers identify genuine security flaws more quickly, they can also produce false positives, inaccurate findings and reports based on AI hallucinations.
Google’s decision follows broader concerns within the cybersecurity community about the impact of AI-generated “slop” on vulnerability disclosure programs. Large volumes of low-quality reports can consume valuable time for security teams, making it harder to identify and investigate legitimate vulnerabilities.
For now, Google is encouraging researchers who want to continue participating in its bug bounty efforts to explore the company’s other vulnerability reward programs. The company is expected to provide more information about the future of its open source program in early 2027.
Google Pauses Open Source Bug Bounty Program Amid Surge in AI-Generated Reports



