The Maivia Gazette

Verified AI news, every morning

Security

Google pauses its open-source bug bounty after a flood of mostly invalid AI-generated reports

The Open Source Software Vulnerability Rewards Program stopped taking product vulnerability reports on October 1, and Google says it will give an update in the first quarter of 2027.

A small reviewing desk buried under a flood of identical blank envelopes in a mail room lit by fluorescent tubes.
AI-generated illustration, not event photography. The motion is AI-generated from the still.

Evidence: Independent reports. Security stories run only with a named disclosure or independent reporting behind them.

Google has stopped accepting new product vulnerability reports through its Open Source Software Vulnerability Rewards Program (OSS VRP). The company says reviewers were overwhelmed by automated submissions. "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid," Google said. According to the program's rules page, the pause took effect on October 1, 2026. TechCrunch, citing Tom's Hardware, reports that Google engineers and open-source maintainers were swamped by reports that were invalid or contained hallucinations. Google launched the OSS VRP in August 2022, with rewards from $100 to $31,337. The program covers open-source projects that Google maintains, including Go, Angular, Bazel, Protocol Buffers and Fuchsia, as well as critical third-party dependencies and repository settings. The pause does not affect supply-chain reports or reports already submitted. In the meantime, researchers can submit security fixes through the Patch Rewards Program, which pays up to $15,000 for high-impact fixes. They can also report flaws in Google Cloud open-source repositories that affect Cloud products through the Cloud VRP. Google says it will keep reworking the program and has committed to an update in the first quarter of 2027. Security experts had already warned that low-quality AI-generated reports were a serious risk to bug bounty programs. Google's decision shows that this flood can take reviewer time away from real vulnerability reports.

Sources

  1. TechCrunchGoogle froze its open source bug bounty program due to a 'significant rise' in AI submissions | TechCrunchPublished · fetched
  2. BleepingComputerGoogle halts open-source bug bounty program amid AI spam surgePublished · fetched
  3. Help Net SecurityAI slop submissions force Google to freeze its open-source bug bounty - Help Net SecurityPublished · fetched

Also in this edition