Google pauses Open Source Software Vulnerability Rewards Program after surge in AI submissions
Google paused its Open Source Software Vulnerability Rewards Program effective October 1, 2026, citing a "significant rise" in automated AI-generated submissions that were largely invalid or hallucinatory; the company said it will provide an update in Q1 2027 and encouraged researchers to use its other bug bounty programs. Reports said Google engineers and maintainers were overwhelmed by the volume and low quality of submissions.