Google Pauses Open-Source Bug Bounty Program Amid Surge in Automated Submissions
Google has temporarily halted new submissions to its Open Source Software Vulnerability Reward Program (OSS VRP) due to an overwhelming surge in automated reports. The program, which rewards security researchers for finding vulnerabilities in Google’s open-source software, has been paused to address the influx of mostly invalid automated submissions.
In a post on X, Google Bug Hunters announced that the OSS VRP would no longer accept product vulnerability submissions for the time being. The company emphasized that supply chain reports and outstanding reports remain unaffected. The decision follows a significant rise in automated submissions, which Google described as largely non-valid.
This is not the first time Google has tightened its OSS VRP rules. Earlier this year, the company adjusted its policies in response to an increase in AI-generated submissions containing incorrect information or minor vulnerabilities. Google plans to rework the program and provide an update in the first quarter of 2027.
Meanwhile, AI-assisted security testing is accelerating vulnerability discovery. In May, Anthropic’s Project Glasswing reportedly uncovered over 10,000 high- or critical-severity vulnerabilities, highlighting the challenges of managing the growing volume of findings in the industry. Researchers can still submit their findings through other vulnerability reward programs or pursue Google’s Patch Rewards Program during the OSS VRP pause.