Google freezes its open-source bug bounty after a flood of AI-generated reports
Google has paused new product-vulnerability submissions to its Open Source Software Vulnerability Rewards Program, blaming a 'significant rise' in automated AI-generated reports, the 'vast majority' of them invalid.
Google has frozen new product-vulnerability submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP), blaming a “significant rise” in automated, AI-generated reports, TechCrunch reported on Oct 4.
The company announced the pause on Oct 1 in posts on X and the program website, saying it will provide “an update” in the first quarter of 2027. “This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” Google said, per TechCrunch. According to Tom’s Hardware, cited in the report, Google engineers and open-source maintainers were overwhelmed by reports that were invalid or contained hallucinations.
The freeze is narrower than a full shutdown: outstanding reports already in the system are unaffected, supply-chain disclosures under the OSS VRP remain open, and some product reports tied to Google Cloud repositories can still go through the separate Cloud VRP. Google is directing researchers toward its other vulnerability-reward programs and its Patch Rewards Program.
TechCrunch noted it had reported last year that cybersecurity experts were warning that AI “slop” posed a serious risk to bug bounty programs. The flood follows a pattern across the industry: Linux maintainers were inundated with bogus AI-generated CVE filings, and Intel recently froze its own bug bounty program amid the same AI-spam bottleneck, the Times of India reported.
More on this topic: all Technology stories


