Google has temporarily suspended new product vulnerability submissions under its Open Source Software Vulnerability Rewards Program after experiencing a sharp influx of invalid security reports generated using artificial intelligence. According to an update to its Bug Hunters program, the company noted that recent months brought a significant rise in automated submissions, with the vast majority failing to point to genuine security flaws. Submissions logged before October 1, 2026, as well as supply-chain reports and items currently under review, will remain unaffected by the pause while Google reorganises the program structure ahead of an update in early 2027.
Background of the Open Source Bounty Scheme and Available Channels
Google launched the initiative in August 2022 to encourage the responsible disclosure of security flaws across open-source projects it maintains, including Golang, Angular, Bazel, Protocol Buffers, and Fuchsia, alongside critical third-party dependencies. The scheme also encompasses repository configurations such as GitHub Actions, application settings, and access-control rules. Financial rewards were structured around severity and impact, with bounties ranging from $100 up to $31,337, primarily emphasizing vulnerabilities that posed substantial threats to the software supply chain.
Despite the temporary freeze on new product vulnerability reports, independent security researchers retain other formal channels to submit findings and receive compensation. Developers who design security patches for open-source code can participate in Google’s Patch Rewards Program, which grants up to $15,000 for high-impact fixes. Additionally, vulnerabilities discovered within Google’s open-source repositories that impact its cloud services remain eligible for reporting through the dedicated Cloud Vulnerability Rewards Program.
Escalating Industry Pressures from Automated Security Submissions
Google’s decision reflects an expanding operational issue across the cybersecurity sector, where automated tools and artificial intelligence are routinely deployed to scan software for flaws. While these systems can assist researchers in detecting potential weaknesses at scale, their widespread application has generated high volumes of inaccurate, incomplete, and low-quality vulnerability claims that burden review teams.
Other prominent technology entities and open-source foundations have recently adjusted their programs in response to similar pressures. In January, maintainers of the curl project ended their bug bounty program on HackerOne after becoming overwhelmed by automated, AI-generated reports that did not constitute actual flaws. In September, Intel eliminated monetary rewards from its Intigriti bug bounty program across its hardware, software, firmware, and services without public explanation, while Microsoft warned in May that the growing speed and scope of automated vulnerability discovery would significantly increase operational burdens on corporate security personnel.
Forthcoming Program Revisions Planned for Early 2027
The growing volume of automated submissions has placed greater scrutiny on how reward programs distinguish verified flaws from synthetic noise. Google confirmed that it is actively reviewing the operational framework of the program to manage low-quality reports more effectively. The company intends to announce formal updates to the process during the first quarter of 2027, establishing revised parameters for researchers reporting flaws across its open-source portfolio.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics