{"slug": "google-pauses-open-source-bug-bounty-program-as-ai-generated-reports-pile-up", "title": "Google pauses open source bug bounty program as AI-generated reports pile up", "summary": "Google is suspending new product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP) starting October 1, 2026, citing a flood of low-quality, AI-generated bug reports that contained hallucinations and described issues with negligible real-world impact. Reports filed before October 1 will still be processed, supply chain reports are unaffected, and certain Cloud-related submissions can still go through Google's Cloud VRP, with a formal update on revised submission rules expected in Q1 2027. Google had already raised the evidence bar for VRP submissions in March 2026, and the Internet Bug Bounty program, Intel, and Linux kernel maintainers have faced similar surges of questionable generative-AI-driven reports.", "body_md": "Google / Wikimedia Commons (Public domain)\n\n# Google pauses open source bug bounty program as AI-generated reports pile up\n\nThe company is suspending new product vulnerability submissions to its OSS VRP, citing a flood of low-quality automated reports that swamped human reviewers\n\n[Google](https://cryptobriefing.com/markets/alphabet/) has hit pause on part of its Open Source Software Vulnerability Reward Program. The reason is a flood of AI-generated bug reports.\n\nStarting October 1, 2026, the company is no longer accepting new product vulnerability submissions to the program, known as the OSS VRP.\n\n## What Google is changing\n\nGoogle tied the suspension to a surge of low-quality, automated reports produced with AI tools. Those reports have been landing on security engineers and on the maintainers of open source projects.\n\nAccording to Google, many of these submissions contained hallucinations. Others described issues with negligible real-world impact.\n\nMost of the submissions in this surge turned out to be invalid. That is a problem because bug bounty programs rely on manual triage. A human has to read each report, try to reproduce the issue, and decide whether it is a real vulnerability.\n\nThe pause is not a full shutdown. Here is how the cutoff works:\n\n- **Reports filed before October 1** will continue to be processed without interruption.\n- **Supply chain reports** are not affected by the suspension.\n- **Certain Cloud-related submissions** can still be sent through Google’s Cloud VRP.\n\nGoogle is also pointing researchers toward its other active reward programs while the OSS VRP pause is in place. It specifically mentioned its Patch Rewards program as an option.\n\n### AI, tech, and the markets they move—in one daily briefing.\n\nDaily. Free. Join 34,000+ readers across crypto, finance, and policy.\n\nThe company says it plans to revise how submissions work. A formal update on those reforms is expected in Q1 2027.\n\n## A problem Google already tried to fix\n\nThis is not Google’s first attempt to manage the problem. In March 2026, the company adjusted its VRP criteria to slow the flow of low-quality reports. The changes raised the bar on the evidence researchers needed to provide.\n\nGoogle also made changes to its reward programs for Android and Chrome during 2026. The OSS VRP suspension is the most aggressive step so far.\n\nGoogle is far from alone. The Internet Bug Bounty program has run into the same issue. So have Intel and the maintainers of the Linux kernel, who have all dealt with rising volumes of questionable reports driven by generative AI.\n\nSome of those programs have responded with pauses and adjustments of their own.\n\n## Why the bounty model is under strain\n\nOpen source projects feel this most acutely. Many are maintained by small teams or volunteers who have no spare capacity to debunk hallucinated vulnerabilities. Google cited the burden on these maintainers directly in explaining the pause.\n\n## What this means\n\nFor security researchers, the immediate effect is a narrower set of places to earn rewards from Google’s open source work. Legitimate researchers who find real flaws in open source products will need to look at other Google VRPs or the Patch Rewards program.\n\nThe Q1 2027 update is the next marker to track. It will show whether Google believes the bounty model can be repaired with better rules, or whether open source security rewards need a different structure entirely.\n\n**Disclosure:** This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our\n\n[Editorial Policy](https://cryptobriefing.com/editorial-policy/).", "url": "https://wpnews.pro/news/google-pauses-open-source-bug-bounty-program-as-ai-generated-reports-pile-up", "canonical_source": "https://cryptobriefing.com/google-pauses-open-source-bug-bounty-ai/", "published_at": "2026-10-04 20:33:52+00:00", "updated_at": "2026-10-04 20:43:01.945521+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "artificial-intelligence"], "entities": ["Google", "Open Source Software Vulnerability Reward Program", "OSS VRP", "Patch Rewards", "Internet Bug Bounty", "Intel", "Linux kernel", "Cloud VRP"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/google-pauses-open-source-bug-bounty-program-as-ai-generated-reports-pile-up", "markdown": "https://wpnews.pro/news/google-pauses-open-source-bug-bounty-program-as-ai-generated-reports-pile-up.md", "text": "https://wpnews.pro/news/google-pauses-open-source-bug-bounty-program-as-ai-generated-reports-pile-up.txt", "jsonld": "https://wpnews.pro/news/google-pauses-open-source-bug-bounty-program-as-ai-generated-reports-pile-up.jsonld"}}