Google has officially paused its open source bug bounty program, known as the OSS VRP, in response to a significant increase in automated vulnerability reports. The company stated that the vast majority of these incoming submissions are invalid, creating a bottleneck that prevents security teams from focusing on genuine threats.
The decision to freeze the program is intended to stop the current queue of reports from growing while Google evaluates potential structural changes. By pausing the intake, the company aims to avoid wasting engineering resources on disproving speculative, duplicated, or hallucinated findings generated by AI tools.
This challenge is not unique to Google. Other organizations have faced similar pressures as generative AI has lowered the barrier to entry for creating polished-looking, yet low-quality, vulnerability reports. Earlier in 2026, the curl project ended its HackerOne bounty program after being overwhelmed by AI-generated submissions, and Intel reportedly stopped offering bounties on its Intigriti program to mitigate a similar flood of reports.
Google has indicated that it plans to reassess the program in the first quarter of 2027. During this hiatus, the company is expected to explore new controls to improve report quality, such as implementing mandatory proof-of-concept requirements, establishing evidence thresholds, and introducing rate limits for submissions.
While the pause is designed to protect the efficiency of security maintainers, it creates uncertainty for legitimate researchers who may find it more difficult to report actual vulnerabilities. The situation highlights a broader issue in disclosure economics, where the cost of generating a plausible report has dropped significantly, while the human-intensive work required to validate or disprove those findings remains high.
