Google pauses product-vulnerability reports in OSS bug bounty program
Google suspended product vulnerability submissions to its Open Source Software Vulnerability Reward Program as of October 1, citing a surge of invalid, AI-generated reports. The company said supply chain reports and Google Cloud VRP submissions are unaffected, and it plans to provide an update on the program by early 2027 while it reworks the process.
GoKawiil's interpretation of the reporting above, not reported fact.
The pause suggests that automated AI tools have made it cheap to generate large volumes of plausible-looking but false bug reports, straining the human review capacity bounty programs depend on. Other open-source projects, such as Linux's handling of network driver bugs, have faced similar issues, which could push companies toward stricter vetting or AI-assisted triage before reinstating such programs.
- Google halted OSS VRP product vulnerability submissions starting October 1
- Cause cited is an overwhelming volume of invalid AI-generated bug reports
- Supply chain reports and Cloud VRP submissions continue; update expected by Q1 2027
Source: tomshardware.com — Etiido Uko, 2026-10-03
Published there as: “Google freezes open-source bug bounty program amid flood of invalid AI slop submissions”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.