Google has stopped accepting most bug reports for its open-source projects, because AI tools buried its engineers in reports that turned out to be wrong.

The freeze started on October 1 and applies to Google's Open Source Software Vulnerability Reward Program, known as the OSS VRP.
Google announced the change on X and promised an update in the first quarter of 2027.
What Google actually paused
A bug bounty pays outside researchers for finding security holes before criminals do. Google's open-source version has run since 2022 and paid from $100 up to $31,337 for flaws in the open-source projects Google publishes.
From October 1, Google no longer takes new reports about security bugs in those projects themselves. Reports already submitted are still being handled, so nobody who filed in good faith loses out.
Two doors stay open. Supply-chain reports - a tampered package or a hijacked build system that could slip bad code into a release - are still accepted, and so are bugs in certain Google Cloud projects through a separate Cloud programme.
Why AI broke it
The problem has a nickname: AI slop. Someone points an AI tool at a code repository, it writes a confident, professional-looking security report in minutes, and the report gets submitted in the hope of a payout.
Most of those reports describe bugs that do not exist, or real quirks with no security impact at all. But every one still has to be read, tested and disproved by a human engineer, which can take hours.
Writing a fake report now costs almost nothing, while checking it costs as much as ever. Once the junk outnumbers the real finds, a bounty stops doing its job.
FFmpeg saw this coming
Google is not the first to give up. The team behind curl, the download tool built into Windows, macOS and billions of devices, shut its bug bounty at the end of January 2026 for the same reason.
The irony is that Google was on the other side of this argument less than a year ago. In November 2025, Google's own AI bug hunter sent a stream of reports to FFmpeg, the volunteer-run project that decodes video for a huge share of the media apps you use.
It is the engine underneath VLC, HandBrake and countless other players and converters.
One report concerned a decoder that only matters for the first few seconds of video in Rebel Assault 2, a game from 1995. FFmpeg called the flood CVE slop and asked Google to either help pay for fixes or stop sending work to unpaid volunteers.
Now Google's own engineers are the ones drowning, and the bounty is on ice.
What it means for you
Nothing on your PC changes today. Google's other bug bounty programmes are still running, and real security flaws in open-source software still get reported and fixed.
The risk is slower fixes if maintainers spend their week clearing junk instead of patching real holes. Real codec bugs do happen - the WebP image bug of 2023 hit browsers and dozens of everyday apps at once.
So the practical advice is the boring one: keep your media software updated. If you use FFmpeg directly, here is how to install and update FFmpeg on Windows.
Quick questions
Has Google shut down all of its bug bounties?
No. Only new product vulnerability reports to the open-source programme are paused. Supply-chain reports, reports already filed and Google's other bounty programmes carry on as before.
What does AI slop mean?
It is slang for low-quality content churned out by AI tools. In security it means bug reports that look convincing but describe problems that are not real, or not dangerous.
When will the programme come back?
Google has only promised an update in the first quarter of 2027. It has not said whether the programme will return in the same form, with new rules, or at all.
Is open-source software less safe now?
Not overnight. Projects still accept security reports, and genuine researchers are still finding and fixing bugs. The worry is slower fixes if volunteers keep losing time to fake reports.
Do I need to do anything?
Only what you should be doing anyway: keep apps such as VLC, HandBrake and FFmpeg on their latest versions, so you get real security fixes as soon as they ship.
The bottom line
AI made bug reports cheap to write and expensive to check, and Google has now hit the same wall as curl and FFmpeg. Tell us what you think the fix should be.
Latest reviews
AllHow to Stream With VLC: Open a Stream URL or Send Your Own
5/5This is amazing! I could no longer afford cable so I cut the cord and started watching Hulu, Youtube, ...
Don't Open a .xmpeg File Before Reading This
3/5It's never a good sign when the potential malware you downloaded has the EXACT same filename as the example. ...
Free Popular IPTV Playlist: Where to Get Fresh, Legal M3U Li...
3/5How can you create a DSTV channels on IPTV?