Home / News EN / Google Suspends Open Source Bug Bounty Program Due to AI Reports

Google Suspends Open Source Bug Bounty Program Due to AI Reports

AI-generated bug reports. Google has suspended, with retroactive effect to October 1, the activities of its Open Source Software Vulnerability Rewards Program (OSS VRP), the initiative dedicated to compensating security researchers for reporting vulnerabilities in software.

AI-generated bug reports

The suspension was necessitated by a significant increase in invalid reports generated via artificial intelligence-based tools. Google’s analysis infrastructure reached operational saturation, preventing the proper processing of actual vulnerabilities.

AI-generated bug reports: why it matters

According to statements from Google, the growing accessibility of large-scale generative tools has encouraged the mass submission of unvalidated reports or those characterized by systematic errors in code analysis. The company specified: “This suspension is due to a significant increase in automatically submitted requests, the vast majority of which are not valid”.

Google highlights an economic disparity in the phenomenon: using API-based scripts to generate dozens of reports incurs minimal costs, while the rewards provided by the OSS VRP for critical vulnerabilities could reach $31,337.

This overload directly impacted internal engineers and open source repository maintainers, forcing them to dedicate hundreds of hours to analyzing complex but inconsistent false positives. Decompiling and verifying synthetic code absorbed critical resources that would have been allocated to fixing real bugs.

What changes and what are the effects

Consequently, the ecosystem has experienced a deterioration in its ability to respond promptly to high-impact reports (legitimate CVEs). The block on the OSS VRP program will remain in effect until the first quarter of 2027, within which period Google has committed to communicating an update on new operational guidelines.

In the meantime, other security reward programs managed by the platform remain regularly active and accessible to accredited researchers. This forced pause represents a necessary setback to rethink preventive authentication mechanisms and counter the abuse of bots used for submitting reports.

Source and further reading on AI-generated bug reports: original article.

* Content created with the assistance of artificial intelligence systems.