Google Pauses Open-Source Bug Bounty After Flood of ‘AI Slop’

Written By
Kezia Jungco
Kezia Jungco
Oct 6, 2026
3 minute read
Google homepage on smartphone.

Google paused new OSS VRP product vulnerability submissions after a surge of invalid automated reports overwhelmed reviewers. Image: Shutter Speed/Unsplash.

eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Bug bounty programs are supposed to uncover vulnerabilities, not bury maintainers in bad reports. Google has paused new product vulnerability submissions to its open-source bug bounty after a surge of automated reports, most of which it says were invalid.

As of Oct. 1, Google is no longer accepting new product vulnerability submissions through its Open Source Software Vulnerability Reward Program, or OSS VRP. Supply chain reports and outstanding cases remain open while Google reworks that part of the program and plans an update in Q1 2027. For security researchers and organizations that rely on open-source software, the pause highlights a growing cost of AI-assisted vulnerability hunting: faster report generation can push more validation work onto maintainers.

Google says most automated submissions were invalid

Google VRP said the pause followed a “significant rise in automated submissions,” adding that the vast majority were not valid. The company encouraged researchers to submit relevant findings through its other vulnerability reward programs or pursue the Patch Rewards Program instead.

Tom’s Hardware reported that Google engineers and open-source maintainers had been overwhelmed by thousands of poorly written reports that claimed to identify bugs but turned out to be invalid or unexploitable. Some reports contained hallucinated findings, forcing reviewers to spend time validating code instead of working on legitimate vulnerabilities.

AI bug hunting is turning triage into the bottleneck

Google launched OSS VRP in 2022 to reward researchers who privately report flaws in its open-source software, including projects such as Go, Angular, and Protocol Buffers. Help Net Security noted that complaints about low-quality, AI-assisted vulnerability reports had already been building across open-source projects and bug bounty programs for months.

Automated tools can produce reports quickly, but maintainers still have to check whether each finding is real and exploitable. For companies running their own disclosure or bounty programs, Google’s pause shows how quickly AI-generated reports can create extra work for security teams. Reviewers still have to separate real vulnerabilities from false positives before engineers can act on them.

Tom’s Hardware also pointed to Linux maintainers who said they were “completely overwhelmed” by vulnerability reports as AI-powered bug hunting increased submission volume. The publication separately noted Intel’s bug bounty suspension, but Intel did not confirm that AI-generated reports caused its decision.

Advertisement

What eWeek found

Google Bug Hunters’ OSS VRP rules show that the pause only affects one part of the program. Other reporting options remain available, including supply chain reports, outstanding submissions, and some Google Cloud-related vulnerabilities through the Cloud VRP.

OSS VRP area

Status

New product vulnerability submissions

Paused as of Oct. 1

Product reports submitted before Oct. 1

Still being processed

OSS supply chain reports

Still accepted

Some Google Cloud repository vulnerabilities

May qualify through Cloud VRP

Patch Rewards Program

Still available for security improvements

Researchers should check the scope of Google’s remaining programs before submitting a finding. For enterprise security teams evaluating AI bug-hunting tools, the broader lesson is to measure reproducible findings and the effort required to validate them, rather than report volume alone.

Google has not said what changes it will make to that part of the program. The company plans to provide an update in Q1 2027.

For more on Google’s security plans, read our breakdown of Google Cloud’s 2029 quantum-security roadmap and what organizations need to know.

Kezia Jungco

Kezia Jungco is a staff writer with five years of hands-on experience testing and analyzing generative AI platforms, chatbots, and NLP tools. She writes in-depth coverage for both enterprise and consumer audiences, focusing on artificial intelligence, data analytics, CRM solutions, cloud infrastructure, cybersecurity, and emerging tech trends. Her work appears in TechRepublic, eWEEK, Datamation, TechnologyAdvice, and Selling Signals.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.