Google has paused product flaw reports to its Open Source Software Vulnerability Reward Program after facing a heavy wave of scripted tickets that staff say are mostly useless [1]. The freeze began on October 1. It stops new product bug entries in public repos until at least the first quarter of 2027 [2]. Security teams found themselves sorting through piles of low-quality files built with large language models, pulling care away from real software defects while developers wait for updates on verified tickets [1]. While coders can still report other security issues, Google bug bounty reviews for open-source product flaws won’t resume until engineers overhaul the intake system [2].
Google Bug Bounty Pauses Product Vulnerability Intake
The move addresses a sharp spike in bot reports sent to the OSS VRP portal and flagged through community channels. In posts published on X and its program website, Google said the pause was needed because scripted entries climbed fast, with the vast majority failing basic validation tests while maintainers struggled to keep pace [1]. Staff responsible for public code repos had spent months reading pages of generated text that claimed to pinpoint exploitable security holes, but most of those tickets pointed to code that worked as intended or described phantom bugs that didn’t exist in the software. That work took months [2].
Google confirmed that the temporary freeze covers only product flaw reports entered into the Google bug bounty portal on or after October 1. The date was October 1. Existing tickets submitted before that date will still work through the normal review queue without being cancelled [2]. The company committed to providing “an update” by the first quarter of 2027 while it reformats how researchers report bugs [1]. Outside analysts must wait. Until that review finishes, outside analysts must hold their product flaw disclosures or test alternative reward tracks provided by the company [2].
Cybersecurity analysts had flagged this exact scenario long before the official freeze took effect. TechCrunch reported last year that experts and program leaders were warning that low-effort bot text posed a real risk to bug bounty work [1]. The rise of accessible AI tools made it easy for amateur bounty hunters to fire scripts at thousands of public repos without checking whether the reported code defects actually existed, creating an immediate triage bottleneck as staff spent hours debunking nonsense instead of patching real security holes [2].

Why Large Language Models Overwhelm Maintainers
Bug hunting in open-source code was historically slow, demanding work that required deep knowledge of logic flaws and memory safety. Testers had to read source code line by line, construct working proof-of-concept exploits, and explain exactly how an attacker could compromise a repo under realistic conditions. The arrival of large language models (LLMs) changed that balance by reducing the cost of writing believable text to almost nothing. Skilled audits gave way to bulk scripts. Anyone with a basic script can now scan codebases, summarize harmless warnings, and generate dozens of professional-sounding bug reports in minutes [2].
The core issue isn’t just report volume, but the persuasive quality of hallucinations. Engineers reported getting huge numbers of poorly written tickets that claimed to uncover serious flaws but fell apart under scrutiny. Verifying even one report forces an engineer to read the code, pull the repo, and try to reproduce the described defect. When bot text invents nonexistent variables or misunderstands basic program flow, teams still lose hours of focused engineering time proving that the reported flaw is entirely imaginary [2].
Google explained the dilemma in clear terms on its program portal. “This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” the company said [1]. Because every ticket demands human care from staff, the deluge forced software teams to spend far more time rejecting false alarms than patching verified security flaws, turning what should have been a helpful crowdsourcing pipeline into an administrative headache that threatened the regular upkeep of vital projects [2].
Google Bug Bounty Program Exemptions and Cloud Reports
The current pause does not shut down the entire Google bug bounty setup. Supply chain reviews remain open. The freeze applies specifically to product flaw files within the OSS VRP, leaving several key reporting channels open to the public. Security testers can still report open-source supply chain flaws without delay under existing OSS VRP rules, as these specialized tracks examine package integrity, build pipelines, and delivery setups rather than isolated code defects or design bugs located inside public repo files [2].
Google also clarified that product flaws impacting cloud setups may still find a home through a separate reward track. Cloud VRP tickets still proceed. Google said it may still accept reports covering product flaws through the Cloud VRP, specifically “for some Google Cloud repos impacting Google Cloud products” during the pause. That carve-out ensures that security flaws affecting hosted enterprise tools still reach internal security engineers without facing the open-source freeze, keeping core cloud services protected while open-source staff rebuild their public intake system [2].

For testers holding other kinds of discoveries, Google encouraged participants to explore its broader family of reward tracks. Bug hunters can instead direct their findings toward Android, Chrome, or core web setups where separate security teams evaluate incoming flaw reports under their own triage rules. Those programs run under separate submission rules and have not announced similar freezes on product reports [1]. Repos stay shut into 2027. For open-source code repos, however, the doors stay shut until the overhaul concludes in 2027 [2].
Linux and Intel Face Similar Automated Pressures
Google isn’t the only major technology organization struggling to manage the sudden wave of automated security reports generated by machine learning tools. Linux maintainers hit similar limits. Earlier this month, Linux staff said they were “completely overwhelmed” by Common Vulnerabilities and Exposures (CVE) claims, especially when automated fuzzers drove kernel defect counts to an all-time peak of 2,000 vulnerabilities during one cycle. Floods of low-effort tickets made it nearly impossible for kernel coders to distinguish between genuine memory bugs and hallucinated code warnings. Kernel maintainers even dropped older network driver support because fake bot tickets drained coding resources [2].
Hardware makers have also pulled back from public bounty programs amid shifting submission patterns. Intel paid $100,000 per bug. Chipmaker Intel halted its vulnerability reward initiative, which previously offered awards reaching $100,000 for a single security flaw, while review teams reconsidered intake rules. While Intel did not officially confirm AI-generated reports as the sole reason for its move, security experts suspect automated entries played a central role, particularly when bounties offer six-figure payouts that give automated hunters strong financial incentives to submit hundreds of speculative claims in hopes of collecting a payout [2].

The broader software industry is grappling with how AI tools disrupt defensive work. While coders adjust safety guardrails after prior industry incidents, such as when OpenAI paused training of its most capable models after breaches, bug bounty programs face a different problem rooted in external triage [1]. Automated tools can write convincing reports in seconds, but human defenders must verify every line of code. That asymmetry gives bot bug hunters an unfair advantage over open-source staff who work with limited time and tight budgets [2].
Next Steps for the Google OSS VRP
Google now faces the challenge of redesigning its intake process before reopening entries in 2027. The hiatus lasts into 2027 [1]. The company indicated that it will spend the hiatus working on this aspect of the program, seeking ways to filter low-effort bot reports before they reach human reviewers. Security testers suggest that future portals might require working proof-of-concept code or bot pre-screening tests before accepting a ticket, because without new defenses, reopening the program would invite the same flood of machine-written tickets [2].
The pause also highlights how open-source software health intersects with modern artificial intelligence. Open-source staff already carry heavy workloads reviewing pull requests, answering user issues, and keeping dependencies secure. When bug bounty incentives attract thousands of unverified reports, staff can’t keep up with their primary coding duties [2]. The Google bug bounty freeze serves as a clear signal that crowdsourced security models must adapt to an era where generating plausible text costs nothing [1].
Security testers and open-source coders will watch closely for Google’s promised update in early 2027. The promised update comes then [1]. Until then, product flaw reports to the OSS VRP remain on hold, setting a clear test for how major tech firms coordinate with outside bug hunters while shaping how other technology firms manage crowdsourced flaw disclosure in the years ahead [2].
- ONLINE NEWS Ha, A. (2026, October 4). Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions. TechCrunch. [Article Link]
- ONLINE NEWS Uko, E. (2026, October 3). Google freezes open-source bug bounty program amid flood of invalid AI slop submissions. Tom’s Hardware. [Article Link]