On October 1, Google stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP). The company says a flood of inaccurate, AI-generated submissions had pulled its engineers and open-source maintainers away from real security fixes. Google plans to share an update on the program's future in the first quarter of 2027.

What is paused and what continues

OSS VRP pays researchers who report flaws and design problems in open-source projects tied to Google. The pause covers new product vulnerability submissions. Reports received before October 1 are still being handled, supply chain reports are unaffected, and Google's other vulnerability reward programs remain open. Google is encouraging participants to use those in the meantime.

A pile of AI-fabricated reports

According to Google, there was a significant rise in automated submissions, the vast majority of which were not valid, and many contained details invented by AI. Vulnerabilities that do not exist, or issues that cannot actually be exploited, were written up with confidence, and each one still takes time to check. Because the program pays rewards, some people apparently used AI to mass-produce reports in the hope that a few would pay out.

Every report has to be reproduced before it can be dismissed, so even a bogus one costs human time. That burden reportedly grew large enough to slow down work on genuinely dangerous bugs, which led to the suspension.

Other programs are feeling it too

The problem is not limited to Google. Intel is also reported to have paused a program that offered up to 100,000 USD (about 15 million yen) per vulnerability, and dealing with low-quality AI reports is becoming a shared challenge across the industry. At the same time, AI is also being used to find real vulnerabilities, so it is working on both the attacking and defending sides.

※1 USD = 150 JPY

Summary

Google halted new product vulnerability reports to OSS VRP from October 1, citing a surge of fabricated AI-generated submissions. Supply chain reports and other reward programs continue, and the outcome of the redesign is due in the first quarter of 2027. The open question is how to keep rewarding good-faith researchers while coping with AI-driven mass submissions.

References

[1] https://www.tomshardware.com/tech-industry/artificial-intelligence/google-suspends-part-of-the-oss-vrp-bug-bounty-program-due-to-an-influx-of-invalid-ai-submissions-product-vulnerability-submissions-ended-october-1