Google Halts Bug Bounty Program Amid AI-Generated Report Flood
Google has temporarily suspended its Open Source Software Vulnerability Reward Program (OSS VRP) due to an influx of invalid AI-generated bug reports. The company announced on October 1 that it would no longer accept product vulnerability submissions, citing the overwhelming number of poorly written and unexploitable 'hallucinations' from automated AI bug-hunting scripts.
The OSS VRP is a specialized security bounty program that incentivizes independent researchers to find and responsibly disclose security flaws across Google's open-source ecosystem. However, with the rise of large language models (LLMs) and AI-powered bug hunters, thousands of low-effort reports have flooded in, overwhelming engineers and maintainers.
This is not an isolated issue, similar scenarios have played out across the industry. Linux maintainers reported being 'completely overwhelmed' by CVE finds after AI-powered bug hunters pushed the Linux kernel to a record 2,000 vulnerabilities per release. Intel also suspended its bug bounty program, which paid up to $100,000 per flaw.
Google has encouraged participants to explore other VRP programs and committed to providing an update by the first quarter of 2027 while it reformats and works on this aspect of the program.