Google Pauses Open Source Bug Bounty Submissions After Flood of Invalid AI Reports
Google paused new product vulnerability reports in its open-source bug bounty program after a surge in automated submissions, most of which were invalid.
Google has paused new product vulnerability submissions to its Open Source Software Vulnerability Rewards Program after what it described as a sharp increase in automated reports, most of which were invalid.
The company announced the pause through its Google VRP account, saying it took effect October 1. Google plans to update the program in the first quarter of 2027.
Automated reports overwhelmed the program
Google said the decision followed a “significant rise” in automated submissions, with most failing to identify valid vulnerabilities. Tom’s Hardware reported that engineers and open-source maintainers were receiving large numbers of invalid reports, including submissions containing AI-generated errors or hallucinated findings.
The issue is largely one of volume and verification: automated tools can generate reports quickly, but maintainers still have to determine whether each claimed vulnerability is real and reproducible.
Google has not shut down the entire OSS program
The pause applies specifically to new product vulnerability submissions. Google’s OSS VRP rules indicate that supply-chain vulnerability reports can still be submitted, while reports already filed before the October 1 cutoff continue to be processed.
The program rewards researchers who discover security weaknesses in Google’s open-source software and related supply chains. During the pause, Google is directing researchers toward its other vulnerability reward programs while it reviews product-level submissions.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0