Google has temporarily shut down its Open Source Software Vulnerability Reward Program (OSS VRP) to product vulnerability submissions, citing an influx of invalid automated reports that are overwhelming the system. The move comes as part of a broader trend in the cybersecurity industry where AI-powered tools are increasingly being used to discover vulnerabilities, but also generating a flood of false positives.
The pause in OSS VRP was announced on October 1, with Google stating that it is due to “a significant rise in automated submissions, the vast majority of which are not valid.” This means that researchers who rely on the program to report vulnerabilities in Google’s open source projects will have to look elsewhere for now. However, existing product vulnerability reports submitted before the pause will still be eligible.
The issue at hand is not just about Google’s OSS VRP, but also a symptom of a larger problem in the bug bounty industry. With the rise of AI-powered tools, researchers are increasingly using automated software to scan code and identify vulnerabilities. While these tools can be incredibly effective, they often produce false positives, which can lead to a flood of invalid reports that clog up the system.
Google is not alone in this challenge. In May, the company made changes to its Chrome and Android reward programs in response to the growing use of AI tools for vulnerability discovery. Standard Chrome payouts were reduced, and the company began favoring concise reports that provide concrete proof a bug exists. For Android, Google said it would prioritize vulnerability types that are harder for AI tools to find.
The Internet Bug Bounty (IBB) program run by HackerOne also paused new submissions in March, citing the speed and volume of AI-assisted vulnerability discoveries as outpacing the open source community’s ability to deliver fixes. This trend highlights the need for a more nuanced approach to bug bounty programs that can handle the increased volume of reports generated by automated tools.
In the meantime, researchers are being encouraged to look elsewhere for rewards. Google is urging them to submit their findings through its Patch Rewards Program, which offers rewards for proactively improving the security of open source projects. This program is designed to incentivize researchers to focus on fixing vulnerabilities rather than just reporting them.
As the bug bounty industry continues to grapple with the challenges posed by AI-powered tools, it’s clear that a more sustainable approach is needed. Google’s temporary pause in OSS VRP serves as a reminder of the need for innovation and collaboration between researchers, developers, and companies to ensure that the benefits of AI are balanced against its limitations.
If you’re involved in bug hunting or rely on bug bounty programs to submit your findings, take note: this trend is likely here to stay. As AI-powered tools become more prevalent, it’s essential to adapt your approach and look for new opportunities to report vulnerabilities and earn rewards. In the meantime, Google will be working to reform its OSS VRP to better handle the influx of automated reports.
Source: SecurityWeek — 2026-10-05