Google has suspended product vulnerability submissions for its Open Source Software Vulnerability Reward Program (OSS VRP) as of October 1, 2026, due to a surge in invalid, AI-generated reports. The influx of automated submissions containing hallucinations overwhelmed security engineers and repository maintainers. Google plans to restructure the program and provide an update in Q1 2027, while keeping supply chain disclosures open and directing researchers to alternative programs.
Impact of AI-Generated submissions on Google
- ▪Google stated that the vast majority of the automated, AI-generated submissions received for its Open Source Software Vulnerability Reward Program were invalid
- ▪Google attributed the pause of its open-source bug bounty program, the Open Source Software Vulnerability Reward Program, to a significant rise in automated, AI-generated submissions
- ▪The influx of invalid, AI-generated reports containing hallucinations overwhelmed Google security engineers and open-source repository maintainers
Details of the program suspension
- ▪Google announced plans to restructure its Open Source Software Vulnerability Reward Program submission framework and provide an official progress update in the first quarter of 2027
- ▪Google suspended product vulnerability submissions for its Open Source Software Vulnerability Reward Program starting October 1, 2026, which does not affect valid filings logged before that date
- ▪Supply chain disclosures submitted under Google's Open Source Software Vulnerability Reward Program remain open despite Google's suspension of product vulnerability reports
Alternative Reward Programs for researchers
- ▪Google directed security researchers to alternative active reward initiatives, including other Google Vulnerability Reward Programs and Google's Patch Rewards Program
- ▪Certain OSS VRP product vulnerability reports tied to Google Cloud repositories may still be accepted through the separate Google Cloud Vulnerability Reward Program
Wider industry impact of AI-Generated reports
- ▪Linux kernel project maintainers dropped support for older network drivers after being flooded by automated, AI-driven Common Vulnerabilities and Exposures filings
- ▪Cybersecurity experts warned in 2025 that low-quality, AI-generated submissions posed a serious risk to bug bounty programs, according to a TechCrunch report
- ▪Chipmaker Intel froze its bug bounty program, which offered payouts up to $100,000, amid what industry analysts described as AI spam bottlenecks
Debatable claims
- ▪Protecting developer bandwidth is more important than maintaining open public vulnerability reporting
- ▪AI-generated vulnerability reports do more harm than good for cybersecurity
- ▪Bug bounty programs should ban all automated AI-generated submissions
- ▪Google's decision to pause its open-source bug bounty program is justified
Story comments
Loading comments…