Google pauses open source bug bounty program as AI-generated reports pile up

48 minutes ago 1



Google has hit pause on part of its Open Source Software Vulnerability Reward Program. The reason is a flood of AI-generated bug reports. Starting October 1, 2026, the company is no longer accepting new product vulnerability submissions to the program, known as the OSS VRP. What Google is changing Google tied the suspension to a surge of low-quality, automated reports produced with AI tools. Those reports have been landing on security engineers and on the maintainers of open source projects. According to Google, many of these submissions contained hallucinations. Others described issues with negligible real-world impact. Most of the submissions in this surge turned out to be invalid. That is a problem because bug bounty programs rely on manual triage. A human has to read each report, try to reproduce the issue, and decide whether it is a real vulnerability. The pause is not a full shutdown. Here is how the cutoff works: Reports filed before October 1 will continue to be processed without interruption. Supply chain reports are not affected by the suspension. Certain Cloud-related submissions can still be sent through Google’s Cloud VRP. Google is also pointing researchers toward its...

Read Entire Article