Google’s Vulnerability Reward Program account said on 1 October that it is “temporarily no longer accepting OSS VRP product vulnerability submissions”, OSS VRP being the open-source arm of its bug bounty. The reason given: “This pause is due to a significant rise in automated submissions, the vast majority of which are not valid.” An update is promised in the first quarter of 2027.
The scope is narrower than the coverage suggests. Google’s notice says the pause “does not impact OSS VRP supply chain reports, or any outstanding reports”. Several outlets reported it as the bug bounty being frozen, halted or killed. On Google’s own account, one report category is shut to new submissions and the rest runs on.
Note the word in the notice: “automated”, not AI-generated. Google’s OSS VRP rules update is more direct, citing “a massive surge in AI-generated reports” and reports with “hallucinations” about how a vulnerability might be triggered. That update also introduced project tiers and required OSS-Fuzz reproduction or a merged patch on the most critical projects, so the tightening predates the pause.
Why it matters: this is the third case in recent weeks of AI-generated volume forcing a research or security pipeline to change its rules, after the arXiv submission cap and new work on spotting AI-written papers. Triage is human and finite.
Sources: Google VRP’s notice and the OSS VRP rules update.
