Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports
Google has stopped accepting new product vulnerability reports through its Open Source Software Vulnerability Rewards Program (OSS VRP), effective October 1, 2026. The company announced the change in a post from its Vulnerability Reward Program account on X, saying the pause is "due to a significant rise in automated submissions, the vast majority of which are not valid." Researchers can no longer submit, or be paid for, security flaws found in the code of flagship OSS VRP projects such as Go, Angular, Bazel, Protocol Buffers, and Fuchsia. Google has not said the flood of low-quality reports was AI-generated, but multiple outlets reported throughout 2026 that reviewers were increasingly struggling with submissions describing hallucinated vulnerabilities — fabricated exploit paths and function calls that do not exist in the actual source.
Details
| Attribute | Value |
|---|---|
| Program | Google Open Source Software Vulnerability Rewards Program (OSS VRP) |
| Change | Product vulnerability report submissions paused |
| Effective Date | October 1, 2026 |
| Announced Via | Post on X from Google's Vulnerability Reward Program account |
| Stated Cause | "A significant rise in automated submissions, the vast majority of which are not valid" |
| Flagship Projects Affected | Go, Angular, Flutter, Bazel, Protocol Buffers, Fuchsia |
| Scope of Pause | 26 flagship-tier and 47 important-tier repositories |
| Removed Reward Ranges | $500–$7,500 (flagship tier), $101–$3,133.70 (important tier) |
| Still Accepted | Supply-chain compromise reports ($500–$31,337) and pre-October-1 submissions |
| Unaffected Programs | Google Cloud VRP, Patch Rewards Program (up to $15,000), other product-specific VRPs |
| Next Update | Google committed to an update in Q1 2027 |
What Changed
The Pause Itself
Google's OSS VRP, launched in August 2022, rewards researchers who find vulnerabilities in the code, build systems, release environments, and dependency chains of open-source projects maintained in public repositories owned by Google organizations. The program sorts covered repositories into four sensitivity tiers; only the top two — flagship and important — carried listed rewards for product vulnerabilities before the pause. Those listings, worth $500 to $7,500 for flagship-tier projects and $101 to $3,133.70 for important-tier projects, were removed from the program page in the same update that added the pause notice. Reports submitted before October 1 are still being processed and paid out under the prior terms.
Why Google Says It Happened
Google's public explanation was brief: a "significant rise in automated submissions, the vast majority of which are not valid." The company did not confirm that AI tools generated the flood, but the timing lines up with warnings raised earlier in 2026 about AI-assisted vulnerability research producing technically fluent but factually wrong reports — plausible-sounding writeups that cite real function names and real files but describe exploit conditions that cannot actually occur, or claim a vulnerable code path is reachable from user input when it is not. Security teams at other organizations, including the maintainers of curl and the Linux kernel, have described similar waves of AI-assisted "slop" reports this year, and HackerOne co-founder Michiel Prins told reporters his own platform has "seen a rise in false positives" tied to automated tooling.
What Is and Is Not Affected
The pause is scoped narrowly to product vulnerability reports against OSS VRP repositories — the category most exposed to mass automated scanning and AI-drafted writeups. Reports describing a supply-chain compromise (such as a hijacked build pipeline, leaked publishing credential, or malicious dependency injection) remain in scope and still carry the program's full reward range of $500 to $31,337. Google's other bug bounty channels are untouched: the Google Cloud VRP, the Patch Rewards Program (paying up to $15,000 for high-impact proactive security improvements), and product-specific programs covering Chrome, Android, and other core Google services continue to operate normally. Researchers with real findings in affected OSS VRP projects are being pointed toward those alternate channels in the interim.
Impact Assessment
| Impact Area | Description |
|---|---|
| Researcher Payouts | Legitimate bug hunters in Go, Angular, Bazel, Protocol Buffers, and Fuchsia lose a direct reward channel until the program resumes |
| Triage Burden | The pause reflects a broader industry problem: security teams spending disproportionate time disproving plausible-looking, AI-drafted but false vulnerability claims |
| Open-Source Maintainer Load | Mirrors reports from curl and Linux kernel maintainers describing similar automated-submission floods straining limited reviewer capacity |
| Program Trust | A prolonged pause risks discouraging skilled researchers from engaging with OSS VRP even after it reopens, if alternatives become habitual |
| Security Coverage Gap | Real vulnerabilities in affected projects may go unreported or unrewarded during the pause, though researchers can still disclose directly to maintainers |
Recommendations
For Security Researchers
- Continue responsible disclosure directly to affected project maintainers even without a reward incentive; most flagship OSS VRP projects retain standard security contact channels
- Route findings in Chrome, Android, Google Cloud, or other covered products through the still-active, product-specific VRPs rather than the paused OSS channel
- If using AI tools to assist vulnerability research, independently verify every claimed exploit path against actual source code and build configuration before submitting — do not forward AI-generated writeups unverified
For Open-Source Project Maintainers
- Expect the AI-generated report problem to persist across other bug bounty and disclosure channels, not just Google's; consider triage safeguards such as requiring a minimal proof-of-concept or reproduction steps before formal review
- Review bot/automation submission policies and rate limits on your own issue trackers and security contact forms
- Track Google's Q1 2027 OSS VRP update for any structural changes (e.g., proof-of-concept requirements, researcher reputation gating) that may be adaptable to other programs
For Organizations Running Bug Bounty Programs
- Evaluate current triage pipelines for resilience against high-volume, technically fluent but invalid submissions, rather than assuming automated noise is rare or easily filtered
- Consider staged verification gates (automated plausibility checks before human review) to reduce reviewer burnout without shutting out legitimate low-effort-but-valid reports
- Monitor industry responses (Google, HackerOne-reported trends, curl, Linux kernel) as a leading indicator for program design adjustments your own bounty program may need
Key Takeaways
- Google paused new OSS VRP product vulnerability submissions effective October 1, 2026, citing a "significant rise in automated submissions, the vast majority of which are not valid."
- Flagship projects affected include Go, Angular, Flutter, Bazel, Protocol Buffers, and Fuchsia, spanning 26 flagship-tier and 47 important-tier repositories.
- Google has not confirmed the submissions were AI-generated, but the pause follows widespread 2026 reporting on AI-assisted "hallucinated" vulnerability reports burdening security teams industry-wide, including at curl, the Linux kernel, and HackerOne.
- Supply-chain compromise reports remain accepted with full rewards up to $31,337, and other Google bounty channels — Cloud VRP, Patch Rewards (up to $15,000), and product-specific programs — are unaffected.
- No resumption date has been set; Google committed only to providing an update in Q1 2027 while it reworks the affected part of the program.
- The episode underscores a growing industry-wide challenge: AI tooling is lowering the cost of generating plausible-sounding but invalid security reports faster than triage pipelines can absorb them.
Sources
- The Hacker News: Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports
- SecurityWeek: Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports
- Cybersecurity News: Google Pauses Open-Source Bug Bounty Program After Flood of Invalid AI-Generated Reports