Google freezes open-source bug bounty program amid flood of invalid AI slop
3 hours ago
- Google suspended product vulnerability submissions to its OSS VRP bug bounty program until 2027 due to an overwhelming influx of invalid AI-generated reports.
- Engineers and open-source maintainers were drowning in thousands of poorly written, hallucinated bug reports, wasting time on manual validation instead of fixing real vulnerabilities.
- Similar issues affected Linux kernel (record high false CVEs) and Intel (suspended bug bounty program), with AI-generated reports suspected as the cause.
- The suspension does not affect supply chain reports or Cloud VRP submissions for Google Cloud products, and submissions made before October 1 are still valid.