Google Suspends Open Source Bug Bounty Program Amid AI-Generated Report Surge
Program pause aims to preserve integrity as automated submissions overwhelm review capacity

Key Takeaways
- Google has temporarily suspended the Open Source Software Vulnerability Rewards Program (OSS VRP).
- The suspension is a response to an influx of AI-generated vulnerability reports overwhelming the review process.
- The move is intended to protect program integrity and ensure legitimate researchers are not delayed.
- Google has not announced a specific date for the program's resumption.
- The incident underscores the need for platforms to adapt verification processes against AI-generated abuse.
Quick answers
- What happened?
- Google has temporarily halted submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) due to a significant increase in AI-generated vulnerability reports. The suspension is intended to manage the influx and protect the program's integrity for legitimate researchers.
- Which products are affected?
- Open Source Software Vulnerability Rewards Program
- What should defenders do?
- Affected vulnerability researchers should monitor official Google security channels for updates on the program's resumption. No immediate patching action is required as this is a program policy change rather than a software vulnerability.
Google has suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP), the company announced. The move comes after the program was flooded with AI-generated vulnerability reports, overwhelming the review process. The suspension is a defensive measure to preserve the program's integrity and ensure that legitimate security researchers can have their findings processed in a timely manner. Google has not specified a resumption date, stating only that the pause is necessary to address the current volume of automated submissions. The Open Source Software Vulnerability Rewards Program is designed to incentivize the discovery and reporting of security bugs in critical open-source software. By suspending submissions, Google aims to reset the backlog and implement measures to filter out automated reports. The decision highlights the growing challenge of AI-generated content in cybersecurity workflows and the need for platforms to adapt their verification processes.
Security Details
Program suspension is a defensive measure taken by Google to manage the influx of AI-generated vulnerability reports. No software vulnerabilities or exploits are being actively tracked; the action is a policy adjustment in response to automated submissions.
Affected products
Open Source Software Vulnerability Rewards Program
Mitigation
Affected vulnerability researchers should monitor official Google security channels for updates on the program's resumption. No immediate patching action is required as this is a program policy change rather than a software vulnerability.
Sources
BleepingComputer
Google halts open-source bug bounty program amid AI spam surge
Oct 5, 2026 · 08:27
Original link
Related Security News

Apple Announces Tighter macOS Full Disk Access Controls Amid AI Agent Security Risks
Apple has announced plans to tighten controls around the macOS Full Disk Access (FDA) setting. The move addresses security risks posed by artificial intelligence agents and some developers exploiting the permission to access sensitive user data—including files, mail, messages, and browsing history—without full user knowledge. The changes will affect how applications request and retain FDA privileges, particularly for AI-related software.



