AI Weekly Malaysia

Back to items Summaries

Google freezes open-source bug bounty program amid flood of invalid AI slop submissions

ID
31419
Status
summarized
Published
03 Oct 2026, 8:00 PM
Fetched
03 Oct 2026, 8:04 PM
Provider
Tom's Hardware
Category
technology
Original URL
https://www.tomshardware.com/tech-industry/artificial-intelligence/google-suspends-part-of-the-oss-vrp-bug-bounty-program-due-to-an-influx-of-invalid-ai-submissions-product-vulnerability-submissions-ended-october-1
Source URL
https://www.tomshardware.com/feeds/all

Summary

Score
7.0
Created
03 Oct 2026, 8:05 PM
Tags
Audience
developersai_agent_usersai_ml_learners

What happened

Google has suspended the product-vulnerability side of its Open Source Software Vulnerability Reward Program (OSS VRP), with submissions ending October 1 and the freeze reportedly running until 2027. Tom's Hardware attributes the halt to a flood of invalid, AI-generated submissions that maintainers describe as hallucinations. The headline frames it as open-source maintainers drowning in low-quality automated reports.

Why it matters

If you run a bug bounty, a security intake form, or any public issue tracker, this is the failure mode to design against now: AI-generated reports can scale faster than humans can triage them, and the cost lands on maintainers, not submitters. The concrete decision is whether to add submission gating (proof-of-concept requirement, reputation thresholds, rate limits, or paid bounties only) before your queue becomes unreadable — Google's answer here was to close the program entirely rather than triage.

Discussion angle

Google's fix was to shut the program down until 2027 — is closing intake the only viable response, or are there gating designs (PoC-required submissions, contributor reputation, paid-only bounties) that keep legitimate reports flowing while filtering AI slop? Worth asking who in the room has already seen this on their own issue tracker.

Top