
Google suspends OSS VRP product vulnerability submissions after flood of invalid AI reports
Google has suspended product vulnerability submissions to its Open Source Software Vulnerability Reward Program after a flood of invalid, AI-generated reports. The pause began October 1, with an update promised by the first quarter of 2027.
Google has suspended product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP), a bug bounty program, after an influx of invalid, AI-generated reports. The company announced the move in an official post on X on October 1, encouraged participants to explore its other vulnerability reward programs, and committed to providing an update on this part of the OSS VRP by the first quarter of 2027.
What changed on October 1
The suspension took effect on October 1, the day it was announced, and does not affect product vulnerabilities submitted before that date. Google said it may still accept some product vulnerability reports through the Cloud VRP, covering Google Cloud repositories that affect Google Cloud products. Supply chain reports filed under the OSS VRP are not affected either.
What the program does
OSS VRP is a specialized Google security bounty program that pays independent researchers for finding and responsibly disclosing flaws across the company's open-source ecosystem. Product vulnerability submissions focus on code defects, logic flaws and design bugs inside Google's public repositories. Finding them was traditionally painstaking manual work that required real skill.
Why the reports flooded in
The rise of large language models (LLMs) and automated AI bug-hunting scripts has nearly eliminated the cost and effort that work required, producing an influx of low-effort, AI-generated reports. Google engineers and open-source maintainers were reportedly overwhelmed by thousands of poorly written submissions that claimed to find bugs but were actually invalid or unexploitable hallucinations. Time went into manually validating code instead of fixing real, critical vulnerabilities.
Similar cases across the industry
Comparable scenarios have been playing out elsewhere. Earlier this month, Linux maintainers said they were completely overwhelmed by CVE findings after AI-powered bug hunters pushed the Linux kernel to a record 2,000 vulnerabilities per release. Intel also suspended its bug bounty program, which paid up to $100,000 per flaw; the company did not officially confirm AI-generated reports as the reason, but experts suspect it was the cause.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.