Tom’s Hardware reports that Google suspended product-vulnerability submissions to its Open Source Software Vulnerability Reward Program on October 1, the day it announced the change in an official post, after a surge of automated reports that were mostly invalid or hallucinated overwhelmed the Google engineers and open-source maintainers who triage them. The pause does not affect supply-chain reports, reports submitted before that date, or product vulnerabilities routed through the Cloud VRP for some Google Cloud repositories, and Google pointed researchers to its other VRP programs and the Patch Rewards program while promising an update in the first quarter of 2027. The report ties the move to Google’s March rules update that tightened evidence requirements against low-impact AI-generated reports and to similar pressure elsewhere, including Intel ending its bug bounty program and Linux kernel maintainers facing a record number of AI-driven CVE findings.
Google suspends OSS VRP product-vulnerability submissions after flood of invalid AI reports
Tom's Hardware reports that Google suspended product-vulnerability submissions to its Open Source Software Vulnerability Reward Program on October 1, the day it announced the change in an official post, after a surge of automated reports that were mostly invalid or hallucinated overwhelmed the Google engineers and open-source maintainers who triage them. The pause does not affect supply-chain reports, reports submitted before that date, or product vulnerabilities routed through the Cloud VRP for some Google Cloud repositories, and Google pointed researchers to its other VRP programs and the Patch Rewards program while promising an update in the first quarter of 2027. The report ties the move to Google's March rules update that tightened evidence requirements against low-impact AI-generated reports and to similar pressure elsewhere, including Intel ending its bug bounty program and Linux kernel maintainers facing a record number of AI-driven CVE findings.
Source: Tomshardware