Google freezes open-source bug bounty program amid flood of invalid AI slop submissions

What happened
Google suspends product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP) over an influx of invalid AI-driven reports. Google has officially suspended product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP) — a bug bounty program — over an influx of invalid AI-driven reports. Google is a software and Internet company based in Mountain View, and its products and services include Software tools.
The company, in an official X post on October 1, encouraged participants to explore other VRP programs and committed to providing an update by the first quarter of 2027, while it reformats and works on this aspect of the program in the meantime. Google said it may still accept reports covering product vulnerabilities through the Cloud VRP, “for some Google Cloud repos impacting Google Cloud products.”
The suspension also does not affect OSS VRP supply chain reports. In a similar case, Linux ended support for older network drivers due to an influx of false AI-generated bug reports .
Key facts
- Google said it may still accept — reports: covering product vulnerabilities through the Cloud VRP, “for some Google Cloud repos impacting Google Cloud products.”
Sources & evidence
- Tom's Hardware Reporting source
Google freezes open-source bug bounty program amid flood of invalid AI slop submissions ↗
https://www.tomshardware.com/tech-industry/artificial-intelligence/google-suspends-part-of-the-oss-vrp-bug-bounty-program-due-to-an-influx-of-invalid-ai-submissions-product-vulnerability-submissions-ended-october-1