Google has temporarily suspended product vulnerability submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after a surge of automated, AI-generated reports overwhelmed the program. The company said the vast majority of these submissions were not valid.

The OSS VRP, launched in August 2022, rewards researchers who responsibly disclose flaws in open-source projects Google maintains, including Golang, Angular, Bazel, Protocol Buffers, and Fuchsia, as well as critical third-party dependencies and repository configurations such as GitHub Actions and access control rules. Rewards under the program have ranged from $100 to $31,337, with a focus on issues affecting the software supply chain.

What Changes, What Doesn’t

Google clarified that the pause applies only to OSS VRP product vulnerability submissions. Supply chain reports and any previously submitted reports are unaffected, and the change does not apply retroactively to product vulnerabilities submitted before October 1, 2026.

Researchers can still pursue other avenues, including the Google Patch Rewards Program, which offers up to $15,000 for high-impact security patches, and the Cloud VRP for vulnerabilities in Google Cloud open-source repositories. Google says it is reworking the OSS VRP’s submission process to address the automation problem and plans to share updates in Q1 2027.

Since launching its first VRP in 2010, Google has paid out more than $81.6 million to researchers. In 2025 alone, it awarded a record $17.1 million to over 700 researchers, a 40 percent jump from 2024’s $12 million.

Part of a Wider Trend

Google joins a growing list of organizations scaling back bounty programs due to low-quality AI-generated submissions. In January, the maintainer of the curl project ended its HackerOne bounty program after being inundated with what it described as AI slop reports. In mid-September, Intel removed financial rewards from its Intigriti bug bounty program without publicly explaining the decision.

Microsoft has also flagged the trend, warning in May that AI tooling is accelerating the pace and breadth of vulnerability discovery across the industry, raising operational demands on security teams. Last month, Microsoft shipped patches for a record 966 flaws, including two actively exploited zero-days, underscoring the scale of the challenge facing vendors managing both real and automated vulnerability reporting pipelines.