The program that pays outside researchers to find flaws in Google's open source code is paused, but supply chain reports and other bug bounty programs (VRPs) remain open.
Google paused the bug bounty program that pays outside researchers to find security flaws in its open-source code on October 1, citing a flood of automated reports that buried its engineers and the open-source maintainers who depend on the program.
The closure is narrow. Only the Open Source Software Vulnerability Reward Program's product-submission lane is closed, according to an announcement on the GoogleVRP X account and the program's rules page. Supply-chain reports, outstanding submissions made before the pause, and Google's other VRPs, including Cloud VRP, remain open.
Google told TechCrunch the pause reflects "a significant rise in automated submissions, the vast majority of which are not valid." Tom's Hardware reported the trigger was engineers and maintainers spending their time on reports that turned out to be fabricated or hallucinated rather than real vulnerabilities.
No public metric on the volume or invalid rate has been released. Google said the next update will come in Q1 2027.
The pause is the first named, scoped institutional response from a major software vendor to a problem news outlets had been warning about for over a year: AI-assisted reporting flooding input channels where the verification cost falls on the receiver. The same dynamic now shows up in code review, peer review, and public comment moderation.