Google freezes open-source bug bounty program over flood of AI slop reports
Google suspended product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP) starting October 1 due to an influx of invalid AI-generated reports. The company pledged an update by Q1 2027, while supply chain reports and Cloud VRP submissions remain open.
- Product vulnerability submissions to OSS VRP halted on October 1
- Google promises an update on the program by Q1 2027
- Supply chain reports and Cloud VRP submissions still accepted
- Intel and Linux faced similar floods of AI-generated bug reports
Read next
Security