Google benches open source bug bounty program following ‘significant rise’ in AI submissions
Google says it will reassess in Q1 2027.
Google has temporarily halted its Open Source Software Vulnerability Rewards Program (OSS VRP) due to a surge in AI-generated bug bounty submissions that are invalid or irrelevant. The company acknowledged that while AI enhances vulnerability discovery, it often produces flawed or incomplete findings, overwhelming the reviewers.
This issue was compounded by AI-driven spam, overwhelming the curl maintainers and Linux security reviewers. Google's decision to pause the OSS VRP aims to reassess the process and develop new solutions. The company previously faced similar challenges with the curl project, which suspended its bug bounty program in early 2026 due to an influx of fabricated vulnerability reports.
Linus Torvalds, the lead maintainer of the Linux security mailing list, also noted that AI-generated reports had made the security list "almost entirely unmanageable" due to duplication and low-quality submissions.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.