Google has hit the pause button on its Open Source Software Vulnerability Reward Programme, citing a massive surge in AI spam contributions.
A rise in low-quality, AI-generated vulnerability reports has driven Google to temporarily halt submissions for its Open Source Software Vulnerability Reward Programme (OSS VRP). Security engineers and maintainers were overwhelmed by the influx of invalid filings, prompting the company to announce an operational freeze on X and on the programme’s website. Google plans to spend this hiatus redesigning its reporting framework and expects to share a progress update in Q1 2027.
The suspension took effect on October 1, though essential security pathways remain active. Valid product submissions filed before October 1 continue to be processed. Disclosures focused on supply chain vulnerabilities under the OSS VRP remain open. Researchers are being redirected towards Google’s other active bug bounty initiatives.
This decision reflects a broader industry strain caused by automated AI spamming tools. Linux maintainers recently faced an overwhelming wave of bogus common vulnerabilities and exposures (CVE) submissions, peaking at 2000 recorded flaws per release, which ultimately forced the project to abandon support for legacy network drivers. Similarly, Intel suspended its own bug bounty program, which offered payouts up to US$100,000 per flaw. While Intel did not cite AI submissions directly, industry analysts point to AI-driven slop bottlenecks as the primary trigger for the shutdown.















































































