Google has temporarily stopped accepting product-vulnerability submissions through its Open Source Software Vulnerability Rewards Program, known as the OSS VRP, blaming a "significant rise" in automated reports — the vast majority of which are not valid. The Google VRP team announced the pause on October 1 on X, and the program's rules page now states that no new product vulnerabilities are being accepted through the channel.
The OSS VRP, launched in 2022, pays security researchers who privately report flaws in Google's open-source software, including projects such as Go, Angular, Bazel, Protocol Buffers, and Fuchsia, as well as repository settings and supply-chain components. Rewards ranged from $100 to more than $31,000. Google engineers and open-source maintainers were spending far too much time triaging thousands of AI-generated reports containing hallucinated vulnerabilities and invented exploit paths instead of fixing real risks, according to TechCrunch, which first reported the freeze. Cybersecurity experts had warned a year earlier that AI-generated "slop" posed exactly this threat to bug bounty programs.
The pause is narrower than a full shutdown. Supply-chain vulnerability reports remain in scope, reports already submitted before October 1 are still being processed, and Google is directing researchers toward its other vulnerability-reward programs and its Patch Rewards program. Google said it will provide an update in the first quarter of 2027. Google is not the first to take this step: in January 2026 the maintainer of the curl utility ended its bug bounty program after a similar deluge of AI-generated reports.



