
Google pauses bug bounties for open source because AI slop reports are drowning its reviewers
Google has temporarily paused its Open Source Software Vulnerability Rewards Program due to an overwhelming influx of low-quality, AI-generated bug reports. The company states that the majority of these submissions are invalid or contain hallucinated data, which strains its human review capacity. While the main program is on hold, Google continues to accept specific high-risk reports and directs researchers to other available bounty programs.
- ▪Google's OSS VRP is no longer accepting new product vulnerability submissions after October 1, 2026.
- ▪The pause was implemented because the vast majority of recent reports are AI-generated slop with invalid information.
- ▪Exceptions are made for supply chain reports and particularly dangerous flaws, which are still being accepted.
- ▪Other major open-source projects like Microsoft Edge and Linux are facing similar issues with AI-generated contributions.
- ▪Google plans to share an update on the future of the program in the first quarter of 2027.
4 outlets in our directory ran this story, first to last over 2 days. All of the coverage we found sits in one bucket: centre. That one-sidedness is itself worth noticing.
- ▪ Google benches open source bug bounty program following ‘significant rise’ in AI submissions — TechRadar
- ▪ Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions — TechCrunch
- ▪ Google freezes open-source bug bounty program amid flood of invalid AI slop submissions — Tom's Hardware
TechSpot files mainly under tech. We currently carry 667 of its stories.
Story provenance
Source · retrieval · rights · ranking — open for full record
inspect →
Story provenance
Attribution is not the same as permission. This drawer separates discovery metadata, excerpts, WeSearch-generated summaries, reuse status, and whether the publisher receives the visit. Nothing here claims a legal grant the publisher has not made.
Record
| Original publisher | TechSpot |
| Canonical URL | https://www.techspot.com/news/114102-google-pauses-bug-bounties-open-source-because-ai.html |
| Publication time | Mon, 5 Oct 2026 15:26 -0500 |
| Retrieval time | 2026-10-05T20:29:56.622Z |
| Last seen | 2026-10-05T20:29:56.622Z |
| Headline source | Publisher (no WeSearch rewrite) |
| Excerpt source | publisher body |
| Excerpt method | First ~120 words (~800 chars) of extracted publisher body, fair-use limited. |
| Summary | WeSearch · cerebras-chat (WeSearch summarizer) |
| Summary source text | contentText |
| Citation coverage | Summary is a WeSearch-generated derivative; primary citation is the original publisher URL. |
| Cluster | EF4tnbNdKoz9 · 4 stories |
| Cluster logic | Grouped by semantic title/content similarity across sources within a rolling window. Same-publisher template collisions are excluded from coverage comparison. |
| Ranking reason | Story pages are not engagement-ranked. Hub feeds use recency, with optional source-diversified chronological ordering (cap consecutive stories per source). No personalized ranking. |
| Publisher visit | Yes — open original |
| Substitutes article? | No — link-out required for full text |
Rights status (four layers)
WeSearch handling by dimension
| Indexing | May the item be indexed (stored, ranked, made findable)? | Allowed |
| Snippet | May a short excerpt of the publisher's text be shown? | Allowed |
| AI summary | May WeSearch generate its own short summary of the article? | Limited |
| Retrieval / RAG | May the content be exposed for third-party retrieval-augmented generation? | Not asserted |
| Model training | May the content be used to train AI models? | Not asserted |
| Commercial reuse | May the content be reused commercially? | Not permitted |
Basis: Derived from the published RSS/Atom feed. Contact: [email protected]. Reviewed: 2026-07-24.
Opening excerpt (first ~120 words) tap to expand
AI Security bug bounty slop Google pauses bug bounties for open source because AI slop reports are drowning its reviewers Microsoft Edge and Linux face the same problem, and smaller projects have banned AI-generated contributions altogether By Alfonso Maruccia October 5, 2026, 15:26 Add TechSpot Serving tech enthusiasts for over 25 years. TechSpot means tech analysis and advice you can trust. Security slop: Generative AI models are exceptionally good at working with code, and vibe coding is now spilling over everywhere. So much so, in fact, that many open-source projects are struggling with an untenable volume of contributions if they want to keep a proper vetting process in place.
…
Excerpt limited to ~120 words for fair-use compliance. The full article is at TechSpot.