Skip to content
Security researcher at a desk with code on screens

TL;DR: Google's Open Source Software Vulnerability Reward Program no longer accepts new product-vulnerability reports as of 1 October 2026 because AI and bot traffic flooded the queue with invalid findings. Reports already in before that date, supply-chain issues, and some Cloud repo bugs via other programs still move. Google promises a reworked process and a Q1 2027 update, not a guaranteed reopen date.

Status note: Checked 5 October 2026 against Anthony Ha's TechCrunch report of 4 October, Tom's Hardware follow-up on maintainer overload, and Google's published OSS VRP rules at bughunters.google.com. Program wording and reopen timing can still change when Google posts its Q1 2027 refresh.

What Google actually paused

Bug bounty programs pay security researchers who find exploitable flaws before criminals do. Google's Open Source Software Vulnerability Reward Program, OSS VRP for short, focuses on vulnerabilities in open-source projects Google maintains or relies on. On 1 October 2026 the company stopped accepting new submissions in the product-vulnerability category for that program.

TechCrunch's Anthony Ha reported the move on 4 October. Google framed it as a response to a significant rise in automated and AI-assisted reports. The vast majority, the company said, were not valid vulnerabilities. Tom's Hardware picked up the same story and quoted engineers saying maintainers were drowning in hallucinated bug write-ups that still demanded human triage.

That triage cost is the point. A bogus report still burns reviewer time, triggers email threads, and can send project maintainers on wild-goose chases through code that was never broken.

How AI slop hit bounties before Google acted

This did not start on 1 October. TechCrunch and other security press warned through 2025 that large language models were spewing low-quality bounty submissions: plausible-sounding CVE-style narratives with no reproducible exploit. Linux kernel and distro maintainers reported similar floods of bogus common vulnerabilities and exposures filings that looked official on paper but fell apart under review.

Google's pause is an operational fix for its own queue, not a industry-wide ban on AI tools in security research. Legitimate hunters still use automation to scan code; the problem is volume of non-vulnerabilities dressed up as critical bugs.

What still works and where to file instead

Google was explicit about what the freeze does not touch. Reports filed before 1 October remain in scope under the prior rules. Supply-chain vulnerability reports through OSS VRP are still accepted. Product issues in some Google Cloud repositories may still route through Google's Cloud VRP rather than the OSS product lane.

Hunters can also use Google's other vulnerability reward programs and the Patch Rewards Program, which pays for upstream fixes in widely used open-source dependencies. None of that disappeared on 1 October. Only the OSS VRP product-vulnerability intake hit pause.

Google said it will reformat this aspect of the program and publish an update in the first quarter of 2027. That is a timeline for news, not a promise that the same submission bucket reopens unchanged on a fixed calendar day.

Researchers who live on bounty income should treat the rules page as live law. Payout tiers, scope lists, and excluded report types can differ between OSS VRP, Cloud VRP, and Patch Rewards even when the brand on the cheque says Google.

Where things stand

Open-source security is not being abandoned here. One high-volume door is shut while Google tries to separate signal from AI noise. Maintainers get breathing room; researchers need to read the current rules page before assuming a report type still pays.

Watch Google's Q1 2027 post for whether product-vulnerability submissions return, in what form, and with what proof-of-concept bar. Until then, treat viral posts claiming Google killed all bug bounties as wrong: this is a lane freeze after an AI junk mail spike, not a company-wide exit from paying for real bugs.

Sources: TechCrunch on the OSS VRP pause, 4 October 2026; Google Open Source Software Vulnerability Reward Program rules.