Google halts bug bounty program amid surge in AI submissions
What's the story
Google has paused its Open Source Software Vulnerability Rewards Program (OSS VRP) due to a "significant rise" in AI submissions. The bug bounty program was paused as of October 1 and will remain in effect until next year. According to Tom's Hardware, the company said it would provide an update on the situation in Q1 2027.
Submission surge
Participants urged to consider other bug bounty programs
The rise in automated submissions, most of which are invalid, has overwhelmed Google engineers and open source maintainers.
The company has urged participants to consider its other bug bounty programs while it works on restructuring the submission framework for the OSS VRP.
This is not an isolated incident as even Linux maintainers have been flooded with bogus Common Vulnerabilities and Exposures (CVE) filings due to automated AI hunters.
Suspension details
Valid product vulnerability filings logged before October 1 not affected
The suspension of the OSS VRP does not affect valid product vulnerability filings logged before October 1. However, it specifically applies to product vulnerability reports.
Supply chain disclosures submitted under the OSS VRP remain open, and certain product vulnerability reports tied to Google Cloud repositories that directly impact Cloud products may still be accepted through the separate Google Cloud VRP.