THE CRUNCH
Google has suspended product vulnerability submissions to its Open Source Software Vulnerability Reward Program, the bug bounty scheme covering flaws in its public open-source repositories. The company announced the pause on October 1, citing an influx of invalid AI-driven reports, and says it will provide an update by the first quarter of 2027 while it reformats that part of the program.
The suspension took effect on October 1, the day of the announcement, and does not affect product vulnerability reports submitted before that date. Google said it may still accept some product vulnerability reports through its Cloud VRP, covering certain Google Cloud repositories, and the freeze does not touch supply chain reports under the OSS VRP. The company asked participants to try its other bug bounty programs in the meantime.
The OSS VRP pays independent researchers to find and responsibly disclose security flaws across Google's open-source repositories, with product vulnerability submissions covering code defects, logic flaws and design bugs. That was traditionally slow, skilled manual work, but large language models and automated bug-hunting scripts have cut the cost and effort to near zero. Google engineers and open-source maintainers were reportedly swamped by thousands of poorly written reports claiming bugs that were actually invalid or unexploitable hallucinations, spending more time validating code than fixing real vulnerabilities.
It is not an isolated case. Earlier this month, Linux maintainers said they were "completely overwhelmed" by CVE finds after AI-powered bug hunters pushed the Linux kernel to a record 2,000 vulnerabilities per release. Intel has also suspended its bug bounty program, which paid up to $100,000 per flaw, and while Intel did not officially confirm AI-generated reports as the reason, experts suspect they played a part.


