Beyond restricting which Gemini models free and AI Plus users can use, Google has also announced that it is hitting pause on the Open Source Software Vulnerability Reward Program (OSS VRP). It’s only this specific bug bounty program that’s being paused, as the internet search giant still recommends bug bounty hunters contribute to other programs, such as the Cloud and AI VRPs, as well as “pursue the Patch Rewards Program”.
The reason for the temporary freeze? According to the announcement, this “is due to a significant rise in automated submissions, the vast majority of which are not valid”. Tom’s Hardware expands on this, noting that “Google engineers and open-source maintainers were reportedly being overwhelmed by thousands of these poorly written reports that claimed to find bugs but were actually completely invalid or unexploitable hallucinations. They ended up spending too much time manually validating code instead of actually fixing real, critical vulnerabilities”.

Google says that it will “continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027”. On one hand, that means any chance of the program coming back will be next year, but on the other, since the company only promised an update, that’s not a guarantee either. And while the company says that it’s not taking in new submissions, the pause will not affect existing ones.
Easiest Prediction From Last Year?
Previously, TechCrunch reported that the cybersecurity industry also raised concerns about AI slop bug bounty reports, and it seems that this Google bug bounty program freeze is the culmination of that. At the time – and a bit ironically – the report cited Vlad Ionescu, the co-founder and CTO of RunSybil, a startup that develops AI-powered bug hunters, who said that “people are receiving reports that sound reasonable, they look technically correct … It turns out it was just a hallucination all along. The technical details were just made up by the LLM”.
(Source: Google [1], [2], Tom’s Hardware, TechCrunch)

