Google has temporarily suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) due to a surge in low-quality, AI-generated vulnerability reports overwhelming the system. The company continues to accept supply chain vulnerability reports and security patches through other programs, and plans to update and relaunch the OSS VRP with improvements in early 2027. This move follows a growing trend of bug bounty programs facing challenges from automated AI report floods.
Google Halts Open-Source Bug Bounty Program Amid AI Spam Surge

