Google suspends open-source vulnerability rewards programme

Google pauses its open-source bug bounty programme
Google has paused its Open Source Software Vulnerability Rewards Program after what it described as a significant rise in automated AI submissions. The pause took effect on October 1, and the company said it plans to provide an update in the first quarter of 2027.
The programme rewards security researchers for reporting vulnerabilities in Google’s open-source software. Google announced the decision in posts on X and on the programme website, while encouraging participants to consider its other bug bounty programmes in the meantime.
Invalid reports are straining triage work
Google said that the vast majority of automated submissions were not valid. Tom’s Hardware reported that Google engineers and open-source maintainers had been overwhelmed by reports that either identified no real vulnerability or contained hallucinated technical claims.
Bug bounty programmes depend on a triage process that distinguishes reproducible security flaws from duplicate, incomplete or inaccurate reports. A high volume of invalid automated reports can consume the time of engineers and maintainers who must assess claims before remediation work can begin.
The decision follows warnings from cybersecurity specialists that AI-generated material, sometimes described as AI slop, could become a serious operational problem for bounty programmes. In this case, Google has chosen to halt intake for the open-source rewards programme rather than continue under the reported level of automated noise.
Other Google bounty programmes remain open
Google did not say when the Open Source Software Vulnerability Rewards Program would resume, beyond committing to an update during the first quarter of 2027. Its statement specifically directs researchers towards the company’s other bug bounty programmes while the open-source programme remains paused.
The pause does not change the importance of vulnerability reporting, but it highlights the need for submissions to contain evidence that a maintainer can verify. For businesses and security teams, the practical implication is to require human review, reproducible steps and clear technical impact before automated findings enter an external disclosure or bounty workflow.

