Google has stopped accepting new product vulnerability reports in its Open Source Software Vulnerability Reward Program, known as OSS VRP, as of October 1, 2026. According to TechCrunch and BleepingComputer, the company blamed a surge of automated submissions, most of which turned out to be invalid.
Google announced the pause on X and on its Bug Hunters site. In the statement, quoted by Help Net Security and Infosecurity Magazine, the company said the pause is "due to a significant rise in automated submissions, the vast majority of which are not valid." Google said it will share an update on the program in the first quarter of 2027.
What the program covers
OSS VRP launched in August 2022. It pays between $100 and $31,337 per vulnerability, depending on severity and on how critical the affected project is, according to BleepingComputer and Infosecurity Magazine. Its scope includes Google-maintained open source projects such as Go, Angular and Protocol Buffers.
Bug bounties exist because outside researchers find flaws that internal teams miss. The trade only works if the reports are worth reading: every submission has to be triaged by a person who tries to reproduce the issue, confirms whether it is real and decides on a payout.
Why automated reports break the model
Generative AI makes it cheap to produce reports that look technical, including ones describing bugs that do not exist. TechCrunch, citing Tom's Hardware, reports that Google engineers and open source maintainers had been dealing with large numbers of invalid reports containing AI hallucinations. Help Net Security notes the pause follows months of complaints about low-quality, AI-assisted submissions hitting bug bounty programs and open source maintainers.
The economics are lopsided. Sending a report now costs almost nothing, while verifying one still takes skilled human time. When the volume of junk rises, the cost lands on the triage team, and valid reports wait longer in the same queue.
Google did not disclose how many reports it received or what share was invalid. Its statement says only that the "vast majority" were not valid.
The timing matters because OSS VRP covers code that sits deep inside other products. Go is used to build server software and cloud tools, Angular runs the front end of many web applications and Protocol Buffers is a common format for exchanging data between services. A real flaw in any of them can travel far beyond Google, which is why a channel that pays outsiders to report such flaws has value, and why clogging it with false reports has a cost for everyone downstream.
What is still open
The freeze applies to product vulnerability reports inside OSS VRP. According to BleepingComputer, Help Net Security and Infosecurity Magazine, these remain unaffected:
- reports submitted before October 1, 2026, which are still being processed;
- supply chain reports, covering flaws in how code is built and distributed, per BleepingComputer and Infosecurity Magazine;
- the Cloud VRP, which covers Google Cloud's open source repositories;
- the Patch Rewards Program, which pays for security improvements to open source projects.
Google is pointing researchers to those programs in the meantime. Infosecurity Magazine reports that the company plans to restructure OSS VRP before reopening it.
What it says about the industry
The decision puts a large company on record saying that AI-generated noise made one of its security programs unworkable in its current form. Bug bounty platforms and individual maintainers have raised the same complaint, as Help Net Security points out, but a pause by Google affects a program that has paid researchers since 2022.
For teams that depend on Go, Angular or Protocol Buffers, nothing changes in the software itself. What stops, until the update promised for the first quarter of 2027, is the payout channel for new product flaws found in those projects through OSS VRP. Google has not said what filters the restructured program will use to keep automated submissions out.


