Google halts open-source bug bounty program over influx of AI-generated reports

 

Google halts open-source bug bounty program over influx of AI-generated reports

Google has temporarily stopped accepting new vulnerability reports for its Open Source Software Vulnerability Rewards Program (OSS VRP) after receiving a large number of AI-generated submissions.

The program, launched in 2022, rewards security researchers for finding vulnerabilities in Google-supported open-source projects such as Golang, Angular, Bazel, Protocol Buffers and Fuchsia. Rewards range from $100 to $31,337.

Google said most of the recent automated submissions were invalid, making it harder for security teams to process legitimate reports. The company said the pause does not affect supply-chain reports or vulnerabilities submitted before October 1, 2026.

Researchers can still report vulnerabilities through Google's other programs, including the Patch Rewards Program and Cloud VRP.

Google said it is working on changes to the OSS VRP and plans to provide an update in the first quarter of 2027.

Google is not the only company that faces problems with AI-generated security reports. The maintainer of curl ended its HackerOne bug bounty program earlier this year after being overwhelmed by low-quality reports.

Last month, Intel reportedly suspended its bug bounty program, which offered security researchers monetary rewards for security flaws. The company quietly updated its bug bounty program page on the Intigriti platform to remove any money payouts and add a "No bounty" marker.

Back to the list