Loading...
Google halts bug bounty program amid surge in AI submissions
The bug bounty program was paused as of October 1

Google halts bug bounty program amid surge in AI submissions

Oct 05, 2026
10:08 am

What's the story

Google has paused its Open Source Software Vulnerability Rewards Program (OSS VRP) due to a "significant rise" in AI submissions. The bug bounty program was paused as of October 1 and will remain in effect until next year. According to Tom's Hardware, the company said it would provide an update on the situation in Q1 2027.

Submission surge

Participants urged to consider other bug bounty programs

The rise in automated submissions, most of which are invalid, has overwhelmed Google engineers and open source maintainers.

The company has urged participants to consider its other bug bounty programs while it works on restructuring the submission framework for the OSS VRP.

This is not an isolated incident as even Linux maintainers have been flooded with bogus Common Vulnerabilities and Exposures (CVE) filings due to automated AI hunters.

Suspension details

Valid product vulnerability filings logged before October 1 not affected

The suspension of the OSS VRP does not affect valid product vulnerability filings logged before October 1. However, it specifically applies to product vulnerability reports.

Supply chain disclosures submitted under the OSS VRP remain open, and certain product vulnerability reports tied to Google Cloud repositories that directly impact Cloud products may still be accepted through the separate Google Cloud VRP.

ADVERTISEMENT