Image: Malwarebytes Labs
Google has temporarily stopped accepting reports through its Open Source Software Vulnerability Rewards Program after a sharp increase in automated submissions. The pause matters mainly to security researchers and open-source maintainers; everyday users do not need to change any Google security settings.
Most automated reports were invalid
Malwarebytes Labs reports that Google paused OSS VRP because automated reports had risen significantly and the vast majority were invalid. Bug bounty programs reward outside researchers for responsibly reporting security flaws.Generative AI can quickly produce polished-looking reports, but each claim may still require a person to prove or disprove it. Invalid and duplicate submissions can therefore consume time that engineers and maintainers could spend fixing confirmed problems.
- Google has not announced the design of a replacement submission process.
- The company has promised an update in the first quarter of 2027.
A wider problem for bounty programs
Google is not alone. Curl ended its HackerOne bounty program in early 2026 after low-quality reports, often generated with AI, overwhelmed its small security team.Intel also launched a program on Intigriti but reportedly removed its available bounties to curb a flood of AI-generated reports. These cases show how cheaper report generation can place a much larger review burden on security teams.
What legitimate researchers can do
Researchers should retain reproducible steps, a working proof of concept and clear evidence of impact while submissions are closed. AI-assisted findings can still be valid, but validation, duplicate checking and proof are essential.Google could eventually add stronger evidence requirements or rate limits, but those ideas have not been confirmed. Until the promised update, details of any redesigned program remain speculative.