Google halts open-source bug bounty program amid AI-generated report surge
Google has temporarily halted its open-source bug bounty program, the Open Source Software Vulnerability Reward Program (OSS VRP), due to a surge in automated submissions. The company cited a significant rise in low-quality, often AI-generated reports that overwhelmed its review process. This is not an isolated issue, other organizations like curl and Intel have also faced similar challenges, leading them to suspend or modify their bug bounty programs.
The pause allows Google to implement better controls, such as mandatory proof-of-concept requirements and rate limits, to filter out invalid submissions. While this move may discourage some legitimate researchers, it aims to prevent engineers from wasting time on disproving speculative or duplicated reports. The company has promised an update on the program's future in Q1 2027.
AI's role in vulnerability discovery is double-edged. On one hand, it lowers the cost of producing polished-looking submissions, leading to mass submissions. On the other, AI-assisted discovery can support real vulnerability findings when coupled with validation and deduplication. The challenge lies in distinguishing valid AI-assisted reports from low-quality ones.
Looking ahead, the solution may involve leveraging AI to handle initial submissions and only passing validated reports to engineering teams. This approach could reduce the burden on human reviewers while ensuring that serious issues receive attention. For now, Google's temporary pause serves as a step toward refining its bug bounty program for better efficiency and effectiveness.