Search

Google Pauses Its Open-Source Bug Bounty After a Flood of AI-Generated Reports

Google Pauses Its Open-Source Bug Bounty After a Flood of AI-Generated Reports

Google stopped accepting product vulnerability reports to its open-source bug bounty on 1 October 2026. The company blames a sharp rise in automated submissions, most of them invalid. It has promised an update in the first quarter of 2027.

Also Read: How Much More Do AI Engineers Actually Make in 2026?

What Google has paused

The programme is the Open Source Software Vulnerability Rewards Program, or OSS VRP. Google launched it in August 2022 to pay researchers who find flaws in its open-source projects.

Also Read: News: Nvidia Nears a

It covers projects such as Go, Angular, Bazel, Protocol Buffers and Fuchsia, with rewards from $100 to $31,337, according to Tech Startups, citing BleepingComputer.

Also Read: News and OpenAI Australia hack

What still works

RouteStatus
OSS VRP product vulnerability reportsPaused from 1 October 2026
OSS VRP supply-chain reportsStill open
Google Cloud VRP and AI VRPOpen, for flaws tied to those products
Patch Rewards ProgramOpen, for security fixes

Google is using the pause to redesign how reports are submitted, Infosecurity Magazine reports.

Also Read: ASOS Hack: What Happened ASOS data breach and What Customers Should Do

Why AI reports broke the programme

A bug bounty assumes reports are scarce and take effort to write. AI tools remove that cost. Anyone can generate a plausible-looking report in seconds.

Also Read: Gemini 4 Argon: Google's Model for Cyber Defenders First - News

The reports still have to be read by a person. Each invalid one takes engineer time to disprove. When most submissions are invalid, the queue stops working for genuine researchers too.

Also Read: ChatGPT Visual Ads: OpenAI Tests Image Ads

What it means for open-source maintainers

Smaller projects face the same reports without Google's staff. A few steps reduce the load.

  • Require a working reproduction. Ask for exact steps or a proof of concept before you triage.
  • Use a report template. Affected version, impact and reproduction as required fields.
  • Publish a security policy. Say what is in scope and how to report privately.
  • Close unreproducible reports quickly. State the reason once and move on.
  • Keep paying attention to real ones. Good researchers are caught in the same queue.

If you maintain a plugin, our series covers the release side: publishing a WordPress plugin with SVN and GitHub Actions and passing WordPress.org review. More engineering guides are in Programming.

TWT Staff

TWT Staff

Writes about Programming, tech news, discuss programming topics for web developers (and Web designers), and talks about SEO tools and techniques

Your experience on this site will be improved by allowing cookies Cookie Policy