Google pauses part of its open-source bug bounty after an AI report surge
OSS VRP(O-S-S V-R-P)
Google's reward program for finding weaknesses in its public software.
open-source software(open source software)
Software whose code is shared publicly.
product vulnerability(product vulnerability)
A software weakness that can create a security problem.
What happened
Google, a technology company that makes online services and software, paused product vulnerability submissions to its Open Source Software Vulnerability Reward Program, or OSS VRP, on October 1. The program pays researchers who report security weaknesses in Google's open-source software. Google said automated submissions had risen sharply, and most were invalid. TechCrunch reported that Google plans to give an update in the first quarter of 2027. TechCrunch report
This is a partial pause, not a shutdown of every Google security channel. Tom's Hardware reported that earlier submissions were not affected. It also said some Cloud VRP reports and supply-chain reports remain outside the pause. Tom's Hardware report
Why the reports overwhelmed the program
AI tools can scan code, suggest possible problems, and write polished reports quickly. That lowers the cost of sending a report. It does not lower the time needed to check whether the claim is real.
Google described this pattern in an official March post. It said it saw a massive surge in AI-generated reports. Some reports invented ways a weakness might be triggered. Others noticed a coding error but showed little security impact. Google changed some rules to require stronger proof, such as an OSS-Fuzz reproduction or a merged patch. For lower project tiers, some product-vulnerability reports no longer earned rewards or credit. Google's official explanation
Why this matters
A bug bounty program depends on a useful signal. Researchers send possible flaws. Engineers and maintainers inspect them, fix real problems, and reward valuable work. If AI makes possible reports nearly free, the checking work becomes the bottleneck.
That creates a difficult tradeoff. AI can help a skilled researcher find patterns faster. It can also produce many confident-sounding mistakes. Each mistake takes human attention. A crowded queue can delay repairs and make serious reports harder to spot. The issue is therefore not simply whether AI finds bugs. It is whether the process can separate evidence from guesses.
What is confirmed
The pause began October 1. It covers product vulnerability submissions in the open-source program. Google blamed the rise in automated submissions and said most were not valid. The company pointed people toward other reward programs. It promised an update in the first quarter of 2027.
What is still unknown
Google has not published the number of invalid reports behind the decision. It has not explained the final design of the replacement process. We also do not know whether the pause hid or delayed any genuine weakness. The reports do not show how many engineers worked on the queue or how much time was lost.
What to watch next
The next important signal will be Google's 2027 update. Watch for requirements that ask for a working reproduction, a clear impact, or a proposed fix. Also watch other open-source projects. If they see the same flood, bug bounty programs may shift from rewarding volume to rewarding evidence. That would change how AI is used in security research without deciding that AI itself is the problem.
Google paused one bug-report program after too many AI reports
📰 Full story: Google pauses part of its open-source bug bounty after an AI report surge
Many automated reports were invalid. Google paused part of its open-source reward program.
OSS VRP(O-S-S V-R-P)
Google's program for rewarding real security reports.
vulnerability(vulnerability)
A weakness that could make software unsafe.
open-source software(open source software)
Software whose code people can view and improve.
💡 The gist
- Google paused one open-source bug-report program on October 1.
- AI-created reports rose sharply, and most were not valid.
- Google plans an update in the first quarter of 2027.
Google, a technology company that makes online services and software, runs a program called OSS VRP. It rewards people who find safety problems in open-source software. Open-source software shares its code publicly.
The program accepts reports about product vulnerabilities. A vulnerability is a weakness that could make software unsafe. Google engineers then check each report.
AI tools can read code and write reports quickly. This makes sending reports cheap. But checking each report still takes human time.
Google said automated submissions had increased greatly. Most were invalid. Some reports claimed problems that did not work. Other reports described harmless code as dangerous. TechCrunch reported this pause.
This created a long checking line. Engineers had to test many claims. They had less time for real security problems. This is why the pause matters. AI can help find clues. It can also create many guesses that sound certain.
Google had already changed its rules earlier. Its official blog asked for stronger proof for some reports. That proof could include a repeatable test or a real code fix. Some lower-tier reports no longer received rewards or credit. Google explained the changes.
The pause does not end every Google security program. Other programs remain available. Reports sent before the pause are not affected, according to Tom's Hardware. Some cloud and supply-chain reports also remain outside the pause. Tom's Hardware reported those limits.
Google has not said how many reports were invalid. It has not shared the final new rules. We also do not know whether any real problem waited longer.
The next update should explain the new system. It may ask for proof before engineers investigate. It may reward fixes more than long reports. Other projects may watch Google's choice.
The big lesson is simple. AI can make reports faster. People still need time to check them. Good security needs both speed and proof.
Google paused a bug-report mailbox because too many notes were wrong
📰 Full story: Google pauses part of its open-source bug bounty after an AI report surge
Many computer problem notes arrived. Most were not true.
Google(Google)
A company that makes computer services.
AI(A-I)
A computer tool that can make words.
Google, a company that makes computer services, has a mailbox-like program.
People can send notes about unsafe software.
Google gives money for a real problem.
AI, a computer tool that can make words, can write many notes quickly.
Some notes were wrong.
Google workers checked each note.
Checking takes time.
Too many wrong notes crowded the line.
So Google paused this part of the program.
Other Google programs still take some notes.
Google plans to explain the next step next year.