Google Pauses Vulnerability Program Amid Invalid AI Reports
Google has temporarily halted its Open Source Software Vulnerability Rewards Program, effective October 1. The decision comes amid a surge in automated submissions, the vast majority of which were deemed invalid. The program, which compensates security researchers for identifying vulnerabilities in Google’s open-source software, will remain on pause until further notice.
According to TechCrunch, citing Tom’s Hardware, Google engineers and project maintainers were inundated with reports that could not be verified or contained AI-generated claims. The influx of false reports overwhelmed the system, prompting the suspension. Participants were advised to explore other Google vulnerability reward programs during this period.
In announcements on X and the program’s website, Google promised to provide an update on the program’s future in the first quarter of 2027. The suspension highlights the challenges of managing vulnerability reports in an era of increasing automation and AI-generated content.