Google has stopped accepting product flaw submissions to its OSS Vulnerability Reward Program, according to a report from Tom's Hardware. The company says a surge of invalid, AI-generated vulnerability reports has overwhelmed the engineers and open-source maintainers who triage them. Google plans to update the program by Q1 2027.
The decision matters because bug bounty programs are a frontline defense for open-source software used across phones, servers and cloud services. When AI tools can churn out plausible-looking reports by the thousand, the human reviewers who separate real bugs from noise become the bottleneck — and the reward system stops working as intended.
Why Google paused OSS vulnerability submissions
According to Tom's Hardware, the OSS Vulnerability Reward Program was hit by thousands of sloppy reports. These submissions look like security findings but contain no real vulnerability, and each one still has to be read, triaged and closed by a person.
That workload is falling on Google engineers and on the open-source maintainers who keep critical projects running. They are reportedly overwhelmed, which pushes real vulnerabilities further down the queue and burns time that would otherwise go into fixes.
- Google has frozen new product flaw submissions to the OSS Vulnerability Reward Program
- The cause is a wave of invalid, AI-driven reports
- Engineers and open-source maintainers are reportedly overwhelmed
- Google plans an update to the program by Q1 2027


