Google Pauses Open-Source Bug Bounty Program After Flood of Invalid AI-Generated Reports

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Google has temporarily stopped accepting new product vulnerability reports through its Open Source Software Vulnerability Reward Program(OSS VRP) following a major increase in automated submissions that were mostly invalid.

The change took effect on October 1, 2026, and Google said it will provide an update on the program in the first quarter of 2027.

The decision does not shut down the entire open-source bug bounty program. Supply-chain vulnerability reports remain in scope, and Google will continue handling product vulnerability reports submitted before October 1.

Some vulnerabilities in Google Cloud repositories may also still be accepted through the separate Google Cloud Vulnerability Reward Program. Google said the pause stemmed from a “significant rise” in automated reports, with the vast majority failing validation.

AI-generated submissions can appear technically convincing while containing invented exploit paths, incorrect assumptions about source code behavior, or claims that a vulnerable function is reachable when it is not. This creates a large triage burden for security engineers and open-source maintainers.

The company had already warned researchers about this problem in earlier OSS VRP rule updates. Google identified AI-generated reports containing incorrect triggering conditions and “hallucinations” about how a vulnerability could be exploited.

The program also tightened evidence requirements for certain reports, particularly memory corruption flaws in high-priority projects.

Google Pauses Open-Source Bug Bounty Program

Google’s OSS VRP covers the latest versions of open-source projects maintained in public repositories owned by Google organizations. It includes issues affecting code, repository settings, GitHub Actions workflows, access controls, build systems, release environments, package publication credentials, and cryptographic signing keys.

The highest-value category remains supply-chain compromise. Researchers can report flaws that could allow an attacker to modify source code, tamper with build artifacts, compromise packages distributed through registries, or abuse build and release infrastructure. Such reports must show a realistic, exploitable path rather than a theoretical risk.

For flagship OT0 projects, supply-chain rewards can range from $3,133.7 to $31,337. Important OT1 projects may receive between $1,337 and $13,337, while standard OT2 projects can qualify for $500 to $3,133.7.

Google does not offer financial rewards for low-priority OT3 repositories. Reward amounts remain subject to the company’s security-impact review.

The paused category is specifically product vulnerabilities. These include software weaknesses such as memory corruption in parsers or network implementations, path traversal flaws, sanitizer failures, and insecure defaults that could substantially affect the confidentiality or integrity of user data in applications built with Google open-source code.

Google’s move highlights a growing problem across vulnerability disclosure programs. Generative AI can help researchers review code, write proof-of-concept material, and identify suspicious patterns.

However, reports still require manual validation, reproducible steps, realistic impact analysis, affected version details, and a clear attack scenario.

Researchers should avoid submitting AI-written findings without verifying them against a recent build. A quality report should include a buildable proof of concept, exact reproduction instructions, crash data where available, evidence that the issue is reachable, and a clear explanation of security impact.

Google is directing researchers toward its other VRP programs and its Patch Rewards Program. At the same time, it is redesigning the paused OSS product-vulnerability intake.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Google Pauses Open-Source Bug Bounty Program After Flood of Invalid AI-Generated Reports appeared first on Cyber Security News.