Skip to main content
The Wire
CyberNews by Zentrya One
Vulnerabilities

Google Pauses Open-Source Product Bug Bounties After Surge in Invalid Automated Reports

Google pauses product vulnerability submissions to its OSS bug bounty program after a surge in invalid automated reports, while supply-chain reports and existing submissions remain unaffected.

Google has temporarily stopped accepting product vulnerability submissions through its Open Source Software Vulnerability Reward Program (OSS VRP) following a sharp increase in automated security reports that the company says are overwhelmingly invalid.

The change took effect on October 1, 2026, affecting vulnerability submissions for major Google-maintained open-source projects including Go, Angular, Flutter, Bazel and Protocol Buffers.

What Has Google Paused?

The change applies specifically to product vulnerabilities—design or implementation flaws within open-source software that could have a meaningful security impact.

Google has not shut down the entire OSS VRP.

Category Current Status
New OSS product vulnerabilities Paused
Supply-chain vulnerability reports Still accepted
Reports submitted before October 1 Still processed
Certain Google Cloud-related flaws May qualify for Cloud VRP
Patch Rewards Program Still available

Google plans to restructure this part of the program and has committed to providing an update in Q1 2027. It has not announced a specific date for reopening product vulnerability submissions.

Automated Reports Overwhelm Vulnerability Triage

Google attributed the decision to a significant increase in automated submissions, saying the vast majority were not valid.

The problem creates a major challenge for vulnerability disclosure programs because security engineers must spend time investigating each submission before determining whether it represents a genuine vulnerability.

The situation can effectively create:

Automated Scanner/Tool → Large Number of Reports → False Positives → Manual Security Review → Increased Triage Workload

Google has not disclosed how many automated reports it received or how many were determined to be invalid.

Is AI Responsible?

AI-assisted vulnerability research has become an important part of the discussion, but there is a key distinction.

Google's October announcement specifically refers to “automated submissions.” It does not state that these submissions were necessarily created using artificial intelligence.

However, Google had already tightened its OSS VRP requirements earlier in 2026 amid concerns about low-quality vulnerability reports, including AI-generated submissions containing incorrect or invented explanations of how vulnerabilities could be exploited.

The Go project's security policy has similarly warned researchers against submitting large amounts of unreviewed LLM-generated vulnerability reports.

The problem is therefore not necessarily the use of AI itself, but submitting automated findings without human validation.

Supply-Chain Bug Bounties Remain Available

Google continues accepting reports involving compromises of the software supply chain.

Examples can include vulnerabilities that allow attackers to:

  • Modify protected source-code branches
  • Compromise build infrastructure
  • Manipulate software releases
  • Obtain package-publishing credentials
  • Tamper with distributed software packages

Rewards for qualifying supply-chain vulnerabilities remain available, reaching up to $31,337 for the highest-priority projects.

Alternative Options for Researchers

Google is encouraging security researchers to investigate whether their findings qualify under another Google vulnerability reward program.

Depending on the issue, researchers may be able to use:

Cloud VRP — Certain vulnerabilities affecting Google Cloud products may remain eligible.

Other Google VRPs — Findings affecting covered Google services may qualify through another program.

Patch Rewards Program — Researchers can potentially receive rewards for accepted security improvements and patches.

Google's Patch Rewards Program offers rewards of up to $15,000 for eligible contributions.

Why This Matters for Bug Bounty Programs

Automated vulnerability discovery can help researchers examine huge codebases much faster than manual analysis alone.

But automation also creates a scaling problem:

Lower Cost of Finding Potential Bugs → More Automated Reports → More False Positives → Higher Human Triage Costs

If researchers submit scanner or AI-generated findings without validating exploitability and security impact, vulnerability programs can become overwhelmed with reports that consume resources without improving security.

The situation demonstrates why future bug bounty programs may increasingly require stronger proof-of-concept evidence, reproducibility and human validation before reports enter full security review.

Security Takeaway

Google's decision should not be interpreted as the company ending its open-source security reward program.

Instead, it is temporarily stopping one category:

OSS Product Vulnerability Submissions

while continuing to accept:

Supply-Chain Reports + Existing Reports + Eligible Reports Through Other Google Programs

The development highlights an emerging challenge for vulnerability disclosure programs as automated and AI-assisted security research becomes increasingly accessible.

AI and automation can help researchers discover legitimate vulnerabilities—but automated output should be treated as a starting point for investigation, not automatically as proof that a vulnerability exists.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.