Program Suspension
Google has officially suspended product vulnerability submissions to its Open Source Software Vulnerability Reward Program — a bug bounty program — over an influx of invalid AI-driven reports. The company encouraged participants to explore other VRP programs and committed to providing an update by the first quarter of 2027 while it reformats and works on this aspect of the program in the meantime.
The suspension went into effect immediately and does not affect product vulnerabilities submitted before that date. Google stated it may still accept reports covering product vulnerabilities through the Cloud VRP for certain Google Cloud repositories impacting Google Cloud products. The suspension also does not affect OSS VRP supply chain reports. In a similar case, Linux ended support for older network drivers due to an influx of false AI-generated bug reports.
Rise of Automated Submissions
OSS VRP is a specialized security bounty program that incentivizes independent researchers to find and responsibly disclose security flaws across Google's open-source ecosystem. Product vulnerability submissions focus on code defects, logic flaws, or design bugs within public repositories. However, the rise of large language models and automated AI bug-hunting scripts has nearly eliminated the cost and effort the task required, leading to an influx of low-effort, AI-generated bug reports.
Engineers and open-source maintainers were reportedly being overwhelmed by thousands of poorly written reports that claimed to find bugs but were actually completely invalid or unexploitable hallucinations. Reviewers ended up spending excessive time manually validating code instead of fixing real, critical vulnerabilities, prompting the suspension of the program.
Industry-Wide Impact
Similar scenarios have been playing out across the tech industry. Linux maintainers reported being completely overwhelmed by vulnerability finds after AI-powered bug hunters pushed the Linux kernel to a record number of CVE reports per release. Intel also suspended its bug bounty program that paid out significant amounts per flaw, with experts suspecting AI-generated reports contributed to the decision.




