Google Pauses OSS Vulnerability Rewards Program Until 2027
Citing a "significant rise" in AI-generated submissions, Google has paused its Open Source Software Vulnerability Rewards Program (OSS VRP) until next year. The program, which rewarded security researchers for discovering vulnerabilities in Google's open source software, has been suspended as of October 1.
AI Slop Overwhelms Security Teams
In 2025, TechCrunch reported that cybersecurity experts were already warning that AI slopβlow-quality, machine-generated contentβposed a serious risk to bug bounty programs. That concern has now materialized at Google. According to Tom's Hardware, Google engineers and open source maintainers were overwhelmed by a flood of reports that were either invalid or contained AI hallucinations.
"This pause is due to a significant rise in automated submissions, the vast majority of which are not valid," the company stated.
What Happens Next
Google announced the pause on X and on the program's website, promising to provide "an update" in the first quarter of 2027. In the meantime, the company is encouraging participants to explore its other bug bounty programs.
The move reflects a broader 2026 trend across the security industry, where organizations are rethinking how to handle AI-driven submissions that strain limited triage resources without delivering actionable findings.
via TechCrunch AI
