
Google has stopped accepting one kind of report through its open-source bug-bounty programme after a surge of low-quality vulnerability submissions. The change, effective October 1, applies to new product-vulnerability reports in the Open Source Software Vulnerability Reward Program, or OSS VRP. It is not a shutdown of Google’s entire bug-bounty operation, and existing reports are not being discarded.
In its announcement to researchers, Google said OSS VRP supply-chain reports and outstanding cases are unaffected. It pointed researchers toward other vulnerability reward programmes where appropriate and promised an update in the first quarter of 2027. That is a date for further information, not a confirmed date for accepting new product reports again.
The immediate problem is triage. A bug report may sound plausible and still describe code that cannot be reached, an exploit that does not work or a flaw with no meaningful security impact. AI tools make it easier to produce such reports at scale, but a human maintainer still has to investigate them. As Tom’s Hardware reported, invalid AI-driven submissions have become a significant burden for the programme.
This has been building for months. In March, Google tightened the OSS VRP rules, requiring stronger proof for some product vulnerabilities and scaling back rewards for lower-priority project tiers. Its security team described AI-generated reports with invented details and reports about bugs with negligible real-world impact. The October pause is a further step after those earlier filters.
There is an uncomfortable irony here. AI may help researchers find genuine weaknesses faster. Google itself has explored that promise with its Big Sleep security agent. Yet the same ability to generate candidate findings cheaply can overwhelm the people responsible for verifying and fixing them. More reports do not automatically mean safer software.
For researchers with a credible finding, the important question now is where it belongs. Google says supply-chain cases can still go through OSS VRP, while some issues affecting Google Cloud products may fit its Cloud VRP rules. Researchers should check the current programme scope before submitting, rather than assuming all open-source product reports have simply moved elsewhere.
The broader lesson is about evidence. Automated discovery can be valuable when it produces a reproducible exploit, a clear impact and enough context for a maintainer to act. Without that, a flood of findings can slow the very security work a bounty programme exists to encourage.







