Google freezes product flaw submissions to its OSS Vulnerability Reward Program over an influx of invalid AI-driven reports, plans an update by Q1 2027
First reported by Tomshardware ·
The ability to report critical flaws in open-source software for rewards is paused until 2027.
Google has halted submissions for its Open Source Software Vulnerability Reward Program (OSS VRP) effective October 1, 2026. The company cited an overwhelming influx of invalid reports generated by artificial intelligence. This suspension is temporary, with Google planning to update the program by the first quarter of 2027 to address the issue. While the OSS VRP is on hold, Google will continue to accept product vulnerability reports for certain Google Cloud repositories through the Cloud VRP. Submissions related to supply chain vulnerabilities within the OSS VRP remain unaffected. This situation mirrors a similar issue faced by Linux, which previously discontinued support for older network drivers due to a surge in erroneous AI-generated bug reports. Google encourages participants to explore other VRP programs during this interim period.
The suspension of Google's OSS VRP program highlights a growing challenge for the cybersecurity community: distinguishing legitimate security findings from AI-generated noise. This move indicates that current AI models are producing a volume of low-quality, often inaccurate, vulnerability reports that are overwhelming human security teams. The Q1 2027 target for an update suggests Google is exploring significant changes to its submission and validation processes, potentially involving AI-detection tools or revised reporting criteria to filter out AI-generated spam effectively.
This development signals a potential bottleneck in the open-source security ecosystem, as maintainers rely on these programs to identify and fix vulnerabilities. The halt could slow down the patching of security flaws in widely used open-source components. Companies and developers relying on these open-source projects may face increased risk if critical vulnerabilities go unreported or unaddressed during this period, necessitating a more proactive internal security stance.
AI-written summary. May contain errors.