Google freezes open-source bug bounty program amid flood of invalid AI slop submissions
- ID
- 31419
- Status
- summarized
- Published
- 03 Oct 2026, 8:00 PM
- Fetched
- 03 Oct 2026, 8:04 PM
- Provider
- Tom's Hardware
- Category
- technology
- Original URL
- https://www.tomshardware.com/tech-industry/artificial-intelligence/google-suspends-part-of-the-oss-vrp-bug-bounty-program-due-to-an-influx-of-invalid-ai-submissions-product-vulnerability-submissions-ended-october-1
- Source URL
- https://www.tomshardware.com/feeds/all
Summary
- Score
- 7.0
- Created
- 03 Oct 2026, 8:05 PM
- Tags
- Audience
- developersai_agent_usersai_ml_learners
What happened
Google has suspended the product-vulnerability side of its Open Source Software Vulnerability Reward Program (OSS VRP), with submissions ending October 1 and the freeze reportedly running until 2027. Tom's Hardware attributes the halt to a flood of invalid, AI-generated submissions that maintainers describe as hallucinations. The headline frames it as open-source maintainers drowning in low-quality automated reports.
Why it matters
If you run a bug bounty, a security intake form, or any public issue tracker, this is the failure mode to design against now: AI-generated reports can scale faster than humans can triage them, and the cost lands on maintainers, not submitters. The concrete decision is whether to add submission gating (proof-of-concept requirement, reputation thresholds, rate limits, or paid bounties only) before your queue becomes unreadable — Google's answer here was to close the program entirely rather than triage.
Discussion angle
Google's fix was to shut the program down until 2027 — is closing intake the only viable response, or are there gating designs (PoC-required submissions, contributor reputation, paid-only bounties) that keep legitimate reports flowing while filtering AI slop? Worth asking who in the room has already seen this on their own issue tracker.