Google has temporarily suspended new product vulnerability submissions to its Open Source Software Vulnerability Rewards Program after being flooded with automated, largely invalid reports generated by AI tools, becoming the latest major technology company to halt or curtail a bug bounty program in response to the same problem. The OSS VRP, launched in August 2022 with rewards ranging from $100 to $31,337, was designed to incentivise responsible disclosure of security flaws across Google-maintained open-source projects including Golang, Angular, Bazel, Protocol Buffers and Fuchsia, as well as critical third-party dependencies and repository configuration issues such as GitHub Actions and access control rules. Google confirmed the pause is specifically due to a significant rise in automated submissions, the vast majority of which are not valid, and said it is working to reformat the program with an update committed for the first quarter of 2027. Researchers can still submit supply chain reports through the OSS VRP, report vulnerabilities in Google Cloud open-source repositories through the Cloud VRP, and pursue security patches through the Google Patch Rewards Program which offers bounties of up to $15,000 for high-impact fixes.
The suspension reflects a broader crisis affecting the bug bounty ecosystem as AI tools become sufficiently capable and accessible to generate plausible-looking vulnerability reports at scale, overwhelming the human reviewers responsible for triaging and validating submissions. Google is not the first major programme to reach a breaking point. In January 2026 the maintainer of the widely used curl command-line utility shut down its HackerOne bug bounty programme entirely after being overwhelmed by what was described as a massive stream of AI-generated low-quality reports. In mid-September Intel removed all financial rewards from its Intigriti bug bounty programme covering software, firmware, hardware and services, without publicly explaining the decision. Microsoft, which has not yet taken equivalent action, warned in May that AI tools are surfacing far more vulnerabilities and that the pace and breadth of vulnerability discovery will increase across the software industry, raising operational demands on security teams. That warning proved prescient when Microsoft released patches in September for a record-breaking 966 flaws in a single month, including two actively exploited zero-day vulnerabilities.
The irony sits at the heart of the current AI security paradox. The same AI capability surge that Google’s own Threat Intelligence Group identified this month as driving vulnerability disclosures to double in eight months, reaching 10,740 in August alone, is simultaneously degrading the quality and trustworthiness of the reporting infrastructure that the security community depends on to manage those vulnerabilities responsibly. Where genuine AI-assisted discovery by skilled researchers is producing high-severity findings at unprecedented speed, the flood of automated low-quality submissions is consuming reviewer bandwidth, eroding programme economics and forcing organisations to shut down or restructure the very systems designed to channel responsible disclosure.