Bug bounty programs are supposed to uncover vulnerabilities, not bury maintainers in bad reports. Google has paused new product vulnerability submissions to its open-source bug bounty after a surge of automated reports, most of which it says were invalid.
As of Oct. 1, Google is no longer accepting new product vulnerability submissions through its Open Source Software Vulnerability Reward Program, or OSS VRP. Supply chain reports and outstanding cases remain open while Google reworks that part of the program and plans an update in Q1 2027. For security researchers and organizations that rely on open-source software, the pause highlights a growing cost of AI-assisted vulnerability hunting: faster report generation can push more validation work onto maintainers.
Google says most automated submissions were invalid
Google VRP said the pause followed a “significant rise in automated submissions,” adding that the vast majority were not valid. The company encouraged researchers to submit relevant findings through its other vulnerability reward programs or pursue the Patch Rewards Program instead.
Tom’s Hardware reported that Google engineers and open-source maintainers had been overwhelmed by thousands of poorly written reports that claimed to identify bugs but turned out to be invalid or unexploitable. Some reports contained hallucinated findings, forcing reviewers to spend time validating code instead of working on legitimate vulnerabilities.
AI bug hunting is turning triage into the bottleneck
Google launched OSS VRP in 2022 to reward researchers who privately report flaws in its open-source software, including projects such as Go, Angular, and Protocol Buffers. Help Net Security noted that complaints about low-quality, AI-assisted vulnerability reports had already been building across open-source projects and bug bounty programs for months.
Automated tools can produce reports quickly, but maintainers still have to check whether each finding is real and exploitable. For companies running their own disclosure or bounty programs, Google’s pause shows how quickly AI-generated reports can create extra work for security teams. Reviewers still have to separate real vulnerabilities from false positives before engineers can act on them.
Tom’s Hardware also pointed to Linux maintainers who said they were “completely overwhelmed” by vulnerability reports as AI-powered bug hunting increased submission volume. The publication separately noted Intel’s bug bounty suspension, but Intel did not confirm that AI-generated reports caused its decision.
What eWeek found
Google Bug Hunters’ OSS VRP rules show that the pause only affects one part of the program. Other reporting options remain available, including supply chain reports, outstanding submissions, and some Google Cloud-related vulnerabilities through the Cloud VRP.
OSS VRP area | Status |
New product vulnerability submissions | Paused as of Oct. 1 |
Product reports submitted before Oct. 1 | Still being processed |
OSS supply chain reports | Still accepted |
Some Google Cloud repository vulnerabilities | May qualify through Cloud VRP |
Patch Rewards Program | Still available for security improvements |
Researchers should check the scope of Google’s remaining programs before submitting a finding. For enterprise security teams evaluating AI bug-hunting tools, the broader lesson is to measure reproducible findings and the effort required to validate them, rather than report volume alone.
Google has not said what changes it will make to that part of the program. The company plans to provide an update in Q1 2027.
For more on Google’s security plans, read our breakdown of Google Cloud’s 2029 quantum-security roadmap and what organizations need to know.


