Google has paused its Open Source Software Vulnerability Rewards Program, citing a surge in automated submissions, most of which it says are not valid.
The program rewards researchers for finding security flaws in Google's open source software. Google paused it on October 1 and promised an update in the first quarter of 2027. In the meantime, it is pointing researchers to its other bug bounty programs.
Google announced the pause in posts on X and on the program's website. It said the pause stems from a significant rise in automated submissions, most of which are invalid. According to Tom's Hardware, Google engineers and open-source maintainers had been overwhelmed by invalid reports, some containing hallucinated details.
The move reflects a problem security experts flagged last year, when they warned that low-quality, AI-generated reports were straining bug bounty programs and draining the time of the people who review them.
For more on AI, security and marketing technology, visit SalesGarners and MarTech360 Hub.
