Google Suspends Open-Source Bug Bounty Due to AI Vulnerability Reports
AI-summarised brief · reviewed before publication
Google announced on Oct. 1 that it is suspending its Open Source Vulnerability Rewards Program (OSS VRP) until the first quarter of 2027. The pause follows a sharp increase in automated AI‑generated bug reports, which Google says are largely invalid. Launched in August 2022, the OSS VRP paid researchers $100 to $31,337 for flaws in Google‑owned open‑source repositories on GitHub and select other platforms, including configuration files such as GitHub Actions workflows. The program does not cover supply‑chain issues or reports already submitted, which will continue to be processed. Google urged researchers to redirect findings to its Cloud VRP, AI VRP, or the Patch Rewards Program while it redesigns the OSS VRP. The decision underscores growing challenges in securing AI‑driven code contributions.
💡 Why It Matters
- · The suspension forces bug‑bounty ecosystems to develop stricter validation methods, curbing AI‑generated noise that can drown out genuine security threats.