Skip to content
Security

Google stops reports of product defects due to AI spam flood

Google has paused new reports of product vulnerabilities in its OSS VRP bug bounty program since October 1, 2026, citing a flood of mostly invalid automated submissions. An update is planned at the earliest for the first quarter of 2027. Affected researchers are referred to Google's other bounty programs for now.

By Brian Beckmann · 5 October 2026 · 3 min

A mailbox with the Google logo is overflowing with paper notes, a robotic arm is stuffing more reports inside.

Google will no longer accept new reports of vulnerabilities in its own products as part of its Bug Bounty Program for Open Source Software, the OSS VRP, starting October 1, 2026. The software company justifies the move with a significant increase in automated submissions, the vast majority of which, according to its own statement, are invalid.

An update on the regulation is expected to be provided by the company no earlier than the first quarter of 2027.

Automated submissions overwhelm the review team

The Open Source Software Vulnerability Rewards Program (OSS VRP) has been paying bounties for vulnerabilities in Google's own open-source projects such as Angular or Golang since 2022. Depending on the severity and project, the bounties range from $100 to $31,337, and even higher for particularly sensitive projects like Bazel or Fuchsia.

Specifically, the category of product vulnerability reports is now paused. Other submission pathways of the program continue to operate. In a statement on X, the responsible team explains that the step was necessary due to a significant increase in automated submissions, the overwhelming majority of which are not valid.

Until an update, Google refers affected researchers to its other bug bounty programs outside the product defect area, as reported by TechCrunch.

The pause specifically affects reports of design or implementation errors in products. Reports of supply chain attacks are still accepted by Google.

This move follows a tightening of regulations in March 2026, when Google already required a technical proof such as an OSS-Fuzz reproduction or a merged patch for certain reporting categories to focus the review on genuine findings.

Curl and HackerOne paused their own programs

Google is not the only organization adjusting its reporting pathways due to the flood of AI-generated bug reports. The Internet Bug Bounty (IBB) from HackerOne also paused new submissions in the spring of 2026. HackerOne justified the move by stating that AI-assisted research is increasing vulnerability findings faster than development teams can fix them.

Historically, according to HackerOne, about 80 percent of IBB bounties went to new findings and only 20 percent to fixes. This ratio, in their own assessment, no longer fits the current situation.

The open-source project curl reacted even more drastically. It completely ended its paid program at the end of January 2026 and even refrained from reviewing incoming reports from early July to early August 2026.

The rate of confirmed genuine vulnerabilities, according to the project, has fallen from about 15 to below 5 percent – an independently unverified figure. Maintainer Daniel Stenberg sums up the situation for small projects: "It is not in our power to change how these people and their slop machines work." Apple also limited the number of open bug reports in its Feedback Assistant program in June 2026 and imposed a 30-day ban on users with too many invalid reports.

It will be crucial whether Google uses the update in the first quarter of 2027 for a technical pre-filtering instead of permanently suspending the category. Small open-source projects like curl lack the capacity that large platforms are currently building to separate genuine findings from AI false reports.

It remains to be seen whether the funding jointly launched by Google, Anthropic, AWS, Microsoft, and OpenAI in March 2026 for open-source security tools will have an effect in time.

Sources

  1. Google froze its open source bug bounty program due to a 'significant rise' in AI submissions
  2. Google VRP – Statement on X regarding the pause of product vulnerability reports
  3. Google suspends part of the OSS VRP bug bounty program due to an influx of invalid AI submissions
  4. Internet Bug Bounty program hits pause on payouts
  5. curl's Summer of Bliss: Why It Stopped Taking Bug Reports in July 2026

Common questions

More on this

Your AI update for the work week

Once a week, the most important AI news – plus one practical tip to try right away. No spam, unsubscribe anytime.

/sicherheit/2026-10/google-oss-vrp-pause-ki-spam /en/security/2026-10/google-oss-vrp-pause-ai-spam