Google stops open source bug bounty program because of AI 'garbage'

Google's OSS VRP program is a reward mechanism to encourage independent security researchers to find and publish security vulnerabilities in the corporation's open source ecosystem.
This used to be complex manual work, requiring highly specialized skills from cybersecurity experts. However, the explosion of large language models and AI-integrated automatic error scanning tools has reduced the cost and effort of creating reports to almost zero. The situation resulted in a wave of poor quality reports flooding the system.
Google's team of engineers and open source project administrators were overwhelmed when they had to process thousands of reports. Most contain false information or result from AI illusions that cannot be exploited in reality. Spending too much time verifying error codes leaves the technical team with insufficient resources to focus on truly serious security issues.

According to the announcement on October 1, Google said that the temporary suspension of receiving product vulnerability reports under OSS VRP takes effect immediately. The company encourages researchers to switch to other bug hunting programs and pledges to release new updates in the first quarter of 2027 after restructuring the process.
This decision does not affect reports submitted before October 1, supply chain reports, as well as some data stores under Google Cloud VRP.
According to Tom's Hardware, Google's move reflects the general situation happening across the technology industry. Previously, the Linux operating system administration community was also overloaded when the number of CVE vulnerabilities searched by AI tools reached a record of 2,000 vulnerabilities per released version, forcing Linux to stop supporting some old network drivers. Intel Corporation also recently quietly suspended its bug bounty program worth up to $100,000 per discovery for similar reasons.
Huy Duc