MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-05 · via BleepingComputer

Google Suspends Open-Source Bug Bounty Program Due to Wave of AI-Generated Submissions

Image via BleepingComputer
Image via BleepingComputer

Google has temporarily halted submissions to its Open Source Software Vulnerability Rewards Program after experiencing a surge of invalid, automated reports generated by artificial intelligence systems. The company maintains its other bounty programs, including patch rewards and cloud vulnerability reporting, while working to redesign the suspended program to filter out low-quality submissions. Google plans to provide updates on program reforms in the first quarter of 2027.

Expanded Detail

Google's decision affects only one component of its vulnerability rewards ecosystem. The company maintains active incentive programs for software patches and cloud-specific vulnerabilities, meaning security researchers have alternative channels for reporting findings. The OSS VRP suspension represents a targeted pause rather than a complete program shutdown, with Google committing to structural improvements by the first quarter of 2027 to implement filtering mechanisms against low-quality submissions.

This suspension reflects a broader industry challenge that has affected multiple organizations recently. Both curl's maintainers and Intel have taken similar actions within the past year, citing overwhelming volumes of AI-generated reports that consume resources without yielding legitimate security disclosures. The volume of invalid submissions has apparently become severe enough that pausing new submissions is considered preferable to continued operational strain.

Context

The suspension could create friction between Google and the security research community that relies on bug bounty programs for income and professional reputation. Researchers may redirect efforts toward competing programs, potentially reducing the diversity of vulnerability discoveries across Google's open-source portfolio. Conversely, the pause may ultimately strengthen the program by forcing development of better validation systems. The broader implication suggests that AI-assisted security tooling, while potentially increasing vulnerability discovery overall, may simultaneously degrade the efficiency of crowdsourced security reporting mechanisms that organizations depend upon.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
AI-Generated False Reports Force Google to Halt Open Source Bug Bounty Initiative · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Google halts open-source bug bounty program amid AI spam surge.” Browse more stories.