Google Pauses Open-Source Bug Bounty Over AI Report Flood

Google stopped accepting new submissions to its open-source bug bounty program after a flood of low-quality, AI-generated vulnerability reports arrived.
Table of Contents
    Add a header to begin generating the table of contents

    Google has stopped accepting new vulnerability submissions to its Open Source Software Vulnerability Rewards Program, a pause that took effect October 1 and was driven by a flood of low-effort, largely hallucinated reports generated by AI tools.

    The company disclosed the pause publicly on October 5, saying the surge of automated submissions had overwhelmed the engineers and maintainers responsible for triaging reports to the program, which covers open-source projects Google maintains.

    AI-Generated “Slop” Reports Overwhelmed Reviewers

    Google said the vast majority of the automated submissions it received were invalid, diverting reviewer attention away from genuine security vulnerabilities that needed attention. The company did not disclose a specific volume of submissions or a percentage breakdown of valid versus invalid reports, but characterized the flood as disruptive enough to justify pausing new intake entirely rather than continuing to triage the backlog as it grew.

    The OSS VRP covers a range of open-source projects maintained by Google, including Golang, Angular, Bazel, Protocol Buffers, and Fuchsia, as well as critical third-party dependencies the company relies on. The program launched in August 2022, offering rewards ranging from $100 to $31,337 for valid vulnerability reports.

    Patch Rewards and Cloud VRP Remain Open

    Google’s separate Patch Rewards Program and its Cloud VRP, which covers vulnerabilities in Google Cloud open-source repositories, remain open and unaffected by the pause. Researchers who would otherwise submit to the OSS VRP are being directed to those two programs in the interim, though neither covers the same scope of projects as the paused program.

    Google said it is redesigning the OSS VRP’s intake process to filter out automated and AI-generated noise, with changes expected to be detailed in the coming months. The company has not given a firm date for reopening the program beyond saying updates will arrive “next year.”

    An Early, Concrete Example of AI “Slop” Disrupting Security Operations

    Google’s decision to pause an entire vulnerability disclosure channel marks one of the first concrete, large-scale examples of AI-generated submissions disrupting a major technology vendor’s security operations. Bug bounty programs have historically had to contend with low-quality submissions from inexperienced researchers, but the scale enabled by generative AI tools — which can produce plausible-sounding but factually hollow vulnerability writeups with minimal human effort — appears to have outpaced what Google’s existing triage process could absorb.

    Why Hallucinated Reports Are Harder to Filter Than Spam

    Unlike traditional spam or low-effort submissions, AI-generated vulnerability reports can mimic the structure, terminology, and technical formatting of legitimate security research, making them harder to immediately dismiss without engineering time spent on review. A report that cites real function names, plausible-sounding attack chains, and standard vulnerability classification language can pass an initial skim even when its core technical claim is fabricated or does not reproduce. That dynamic forces reviewers to invest meaningfully more time per submission than they would for an obviously low-quality report, which compounds the triage burden as submission volume grows.

    Security researchers have raised concerns in recent years about the broader trend of AI tools being used to mass-produce vulnerability reports, pull requests, and bug bounty submissions across the industry, since the asymmetry between how quickly an AI tool can generate a plausible-looking report and how long a human reviewer needs to verify it favors the submitter over the triaging organization. Google’s pause represents one of the clearest public acknowledgments yet that this asymmetry can force a security team to shut down intake entirely rather than attempt to keep pace.

    Impact on Legitimate Open-Source Researchers

    Legitimate vulnerability researchers currently have no path to submit new reports or receive rewards through the OSS VRP until Google completes its redesign of the intake process. For a program that has run continuously since its launch and covers widely used projects like Golang and Angular, an open-ended pause removes a formal incentive and disclosure channel that researchers have relied on to responsibly report flaws in Google-maintained open-source code.

    Whether other major vendors running similar open-source bug bounty programs face comparable pressure from AI-generated submissions remains an open question, though Google’s experience suggests the industry may need new verification mechanisms — beyond manual triage — to keep pace with the volume AI tools can now generate on the submitter side of the disclosure pipeline.

    Related Posts