Google pauses open-source bug bounty program amid AI spam surge
Google has temporarily halted new submissions to its Open Source Software Vulnerability Reward Program (OSS VRP) due to an overwhelming number of invalid, AI-generated reports. The pause took effect on October 1, 2023, as announced in an official X post. The OSS VRP, which rewards security researchers for identifying flaws in Google's open-source projects like Go and Angular, has been inundated with low-quality submissions.
Submissions made before the pause are still being processed, and the company may continue accepting reports through its Cloud VRP for Google Cloud repositories affecting Cloud products. Google plans to revisit and improve the OSS VRP, with an update expected in Q1 2027. In the meantime, researchers are encouraged to submit findings to other VRP programs or the Patch Rewards Program, which compensates for security improvements in Google's open-source projects.
The decision follows months of complaints from open-source maintainers and bug bounty programs about the surge in AI-assisted, low-quality vulnerability reports. The program's scope includes design or implementation issues in Google OSS that significantly impact user data confidentiality or integrity. Criteria for accepting reports vary based on the project's tier and the vulnerability's subcategory.