Google halts open-source bug bounty program amid AI spam surge
Google has temporarily halted its Open Source Software Vulnerability Reward Program (OSS VRP) due to an overwhelming surge of invalid, AI-generated bug reports. The pause, effective October 1, 2024, aims to restructure the submission framework and reduce the burden on security engineers and repository maintainers. Google plans to provide an update on the program's progress by the first quarter of 2027.
The suspension applies specifically to product vulnerability reports, though supply chain disclosures under the OSS VRP remain open. Additionally, reports tied to Google Cloud repositories that impact Cloud products can still be submitted through the separate Google Cloud VRP. Existing valid reports filed before October 1 will also be processed.
This move follows similar actions by other tech companies, including Linux maintainers and chipmaker Intel. Linux maintainers reported being inundated with bogus Common Vulnerabilities and Exposures (CVE) filings, forcing them to drop support for older network drivers. Intel recently froze its bug bounty program, with industry analysts attributing the shutdown to AI spam bottlenecks.
Google encouraged security researchers to explore other active reward initiatives, such as the Patch Rewards Program, during the suspension period. The company acknowledged the need to address the influx of automated submissions, which have made it difficult to identify legitimate vulnerabilities.