Google suspends open-source bug bounty program due to surge in invalid AI-generated submissions
The suspension affects product vulnerability submissions until 2027, as maintainers struggle with an influx of low-quality reports. The company encourages participants to explore other VRP programs while it reevaluates its approach.

Google has suspended product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP) due to an overwhelming number of invalid reports generated by AI tools. The company announced the freeze on October 1, citing the need to address the growing volume of low-quality submissions that are overwhelming maintainers and developers.
The decision follows reports that engineers and open-source maintainers are struggling to manage thousands of sloppy and hallucinated vulnerability reports. Many of these submissions are being flagged as invalid, leading to a significant strain on the program’s resources and effectiveness. The suspension aims to give Google time to restructure the program and implement measures to filter out non-viable reports.
The freeze is set to last until the first quarter of 2027, during which time Google will work on reformulating its processes and improving the quality of submissions. The company has directed participants to consider alternative VRP programs in the interim, while it commits to providing an update by early 2027. This move reflects a broader challenge in managing AI-generated content within security and open-source communities.
The suspension has broader implications for the open-source security ecosystem, potentially increasing the cost and complexity of vulnerability management for maintainers. It may also lead to increased vendor lock-in as developers seek alternative programs. The market reaction has been mixed, with some viewing the move as a necessary step to address systemic issues in AI-generated submissions, while others express concerns about the long-term impact on collaboration and transparency.
As the situation develops, the focus remains on how Google will restructure its OSS VRP to better handle AI-generated submissions. The outcome of this effort will be critical in determining the future of open-source security programs and their ability to adapt to the growing influence of AI in the software development landscape.
Sources
- https://techcrunch.com/2026/10/04/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions/
- https://www.tomshardware.com/tech-industry/artificial-intelligence/google-suspends-part-of-the-oss-vrp-bug-bounty-program-due-to-an-influx-of-invalid-ai-submissions-product-vulnerability-submissions-ended-october-1