X

Google Freezes Its Open Source Bug Bounty After a Flood of Junk AI Reports

Google has stopped accepting most bug reports for its open-source projects, because AI tools buried its engineers in reports that turned out to be wrong.

A letter tray buried under a tower of identical robot-stamped bug report cards with a PAUSED tag, one real report set apart under a magnifying glass, beside the title AI reports freeze Google bug bounty

The freeze started on October 1 and applies to Google's Open Source Software Vulnerability Reward Program, known as the OSS VRP.

Google announced the change on X and promised an update in the first quarter of 2027.

What Google actually paused

A bug bounty pays outside researchers for finding security holes before criminals do. Google's open-source version has run since 2022 and paid from $100 up to $31,337 for flaws in the open-source projects Google publishes.

From October 1, Google no longer takes new reports about security bugs in those projects themselves. Reports already submitted are still being handled, so nobody who filed in good faith loses out.

Two doors stay open. Supply-chain reports - a tampered package or a hijacked build system that could slip bad code into a release - are still accepted, and so are bugs in certain Google Cloud projects through a separate Cloud programme.

Why AI broke it

The problem has a nickname: AI slop. Someone points an AI tool at a code repository, it writes a confident, professional-looking security report in minutes, and the report gets submitted in the hope of a payout.

Most of those reports describe bugs that do not exist, or real quirks with no security impact at all. But every one still has to be read, tested and disproved by a human engineer, which can take hours.

Writing a fake report now costs almost nothing, while checking it costs as much as ever. Once the junk outnumbers the real finds, a bounty stops doing its job.

FFmpeg saw this coming

Google is not the first to give up. The team behind curl, the download tool built into Windows, macOS and billions of devices, shut its bug bounty at the end of January 2026 for the same reason.

The irony is that Google was on the other side of this argument less than a year ago. In November 2025, Google's own AI bug hunter sent a stream of reports to FFmpeg, the volunteer-run project that decodes video for a huge share of the media apps you use.

It is the engine underneath VLC, HandBrake and countless other players and converters.

One report concerned a decoder that only matters for the first few seconds of video in Rebel Assault 2, a game from 1995. FFmpeg called the flood CVE slop and asked Google to either help pay for fixes or stop sending work to unpaid volunteers.

Now Google's own engineers are the ones drowning, and the bounty is on ice.

What it means for you

Nothing on your PC changes today. Google's other bug bounty programmes are still running, and real security flaws in open-source software still get reported and fixed.

The risk is slower fixes if maintainers spend their week clearing junk instead of patching real holes. Real codec bugs do happen - the WebP image bug of 2023 hit browsers and dozens of everyday apps at once.

So the practical advice is the boring one: keep your media software updated. If you use FFmpeg directly, here is how to install and update FFmpeg on Windows.

Quick questions

Has Google shut down all of its bug bounties?

No. Only new product vulnerability reports to the open-source programme are paused. Supply-chain reports, reports already filed and Google's other bounty programmes carry on as before.

What does AI slop mean?

It is slang for low-quality content churned out by AI tools. In security it means bug reports that look convincing but describe problems that are not real, or not dangerous.

When will the programme come back?

Google has only promised an update in the first quarter of 2027. It has not said whether the programme will return in the same form, with new rules, or at all.

Is open-source software less safe now?

Not overnight. Projects still accept security reports, and genuine researchers are still finding and fixing bugs. The worry is slower fixes if volunteers keep losing time to fake reports.

Do I need to do anything?

Only what you should be doing anyway: keep apps such as VLC, HandBrake and FFmpeg on their latest versions, so you get real security fixes as soon as they ship.

The bottom line

AI made bug reports cheap to write and expensive to check, and Google has now hit the same wall as curl and FFmpeg. Tell us what you think the fix should be.

LATEST REVIEWS (0)
Be the First to Write a COMMENT!
Verification Code
Click the image or refresh button to get a new code.
Quick heads up: Reviews & comments get a fast check before posting - no spam allowed.
Link copied to clipboard!