Google has suspended its Open Source Software Vulnerability Rewards Program effective October 1, citing what the company characterizes as a "significant rise in automated submissions." The search giant announced the freeze through posts on X and its program website, pledging to issue an update during the first quarter of 2027. The pause represents a major disruption to a program that has historically incentivized security researchers to identify vulnerabilities in Google's open source software contributions.
The root cause of the suspension points to an influx of AI-generated bug reports that lack validity. Google engineers and open source maintainers have been overwhelmed by submissions that are either entirely invalid or contain hallucinations—false information generated by large language models attempting to identify security flaws. The vast majority of these automated submissions do not represent genuine vulnerabilities, forcing human reviewers to sift through noise rather than legitimate security research. This phenomenon had been anticipated by cybersecurity experts, who warned throughout the prior year that artificial intelligence posed a serious risk to the integrity of bug bounty programs.
The situation reflects a growing tension between the proliferation of AI tools and the sustainability of crowdsourced security research programs. Bug bounties have traditionally served as a critical mechanism for identifying and remediating software vulnerabilities before malicious actors could exploit them. When these programs become inundated with low-quality, AI-generated submissions, they lose effectiveness both as security tools and as opportunities for legitimate researchers to contribute. Google's decision to pause the program suggests that the volume and quality degradation has reached a breaking point where continuing operations would waste resources without meaningful security benefit.
While the open source program remains frozen, Google is directing participants toward its other bug bounty initiatives. The company has not indicated which alternative programs it considers most relevant for researchers previously focused on open source vulnerabilities. The timeline for resumption—potentially months away given the Q1 2027 target for updates—leaves a gap in crowdsourced vulnerability discovery for Google's open source projects, including widely-used libraries and tools that many developers depend upon. The company will need to develop filtering mechanisms, verification systems, or submission requirements to prevent a recurrence of the AI submission surge when the program eventually reopens.
Gist is a free AI reader for your browser, iPhone, and Android. Get concise summaries and key takeaways from any article or podcast.
Get Gist — Free