Cybersecurity

Google Suspends Intake of Vulnerability Reports in Its Open-Source Projects Due to AI-Generated Reports

Google has temporarily suspended the intake of product vulnerability reports under the OSS VRP after a large influx of automated reports, saying that most of them were invalid. Supply-chain reports and some reports through other bug bounty programs will continue to be accepted, with the company set to announce program changes in the first quarter of 2027.

2026-10-05
3 min read
33 views
certi.news Editorial Team
Google Suspends Intake of Vulnerability Reports in Its Open-Source Projects Due to AI-Generated Reports

Google has temporarily suspended the intake of product vulnerability reports under the Open Source Software Vulnerability Reward Program (OSS VRP) after facing a large influx of automatically generated or submitted reports, saying that the vast majority of them were invalid.

The program covers open-source projects managed by Google, including Golang, Angular, Bazel, Protocol Buffers, and Fuchsia, in addition to external dependencies that have an impact on the software supply chain. It also covers repository configurations, such as GitHub Actions, application configurations, and access-control rules.

What Has Actually Changed?

Google launched the OSS VRP in August 2022, with rewards ranging from $100 to $31,337 and a stated focus on flaws with the greatest impact on the software supply chain. The company said the suspension does not include supply-chain reports or existing reports, and does not affect product vulnerabilities submitted before October 1, 2026.

Google explained that it is resetting the program to address the issue of automated reports and will provide details of the changes in the first quarter of 2027. During the suspension period, researchers can submit open-source software patches through the Google Patch Rewards program, which offers rewards of up to $15,000 for high-impact fixes, or report vulnerabilities in Google Cloud open-source repositories if they affect Cloud products through the Cloud VRP.

Why Does This News Matter?

The decision shows that artificial-intelligence tools not only increase researchers’ ability to discover flaws, but may also raise the cost of triaging and verifying reports. When low-quality reports overwhelm disclosure channels, operators may be forced to temporarily scale back an entire intake channel, even if the original goal was to improve open-source software security.

The move comes in a broader context. In January, the maintainer of the curl tool ended its vulnerability bounty program on HackerOne after an influx of what the source described as poor-quality, AI-generated reports. Intel also removed financial rewards in mid-September for reported flaws in its software, firmware, hardware, and services submitted through Intigriti, without publicly explaining the decision. In May, Microsoft warned that artificial-intelligence tools would increase the speed and scale of vulnerability discovery and raise operational requirements across the industry.

The Broader Context of Google’s Programs

Since launching its first vulnerability reward program in 2010, Google has paid more than $81.6 million to thousands of researchers. In 2025 alone, it paid $17.1 million to more than 700 researchers, an increase of 40% compared with $12 million in 2024.

The current suspension does not represent a comprehensive shutdown of Google’s security programs, but it temporarily changes the reporting path for product vulnerabilities in its open-source projects. The effectiveness of the OSS VRP redesign will remain tied to the company’s ability to distinguish useful automation from unverifiable reports without weakening researchers’ access to a disclosure channel.

News source
BleepingComputer
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news