Google Freezes Open-Source Bug Bounty Over AI Submission Issues

www.news4hackers.com-google-freezes-open-source-bug-bounty-over-ai-submission-issues-google-freezes-open-source-bug-bounty-over-ai-submission-issues

Google has suspended new vulnerability reports for its Open Source Software Vulnerability Reward Program (OSS VRP) following an influx of automated, non-validated submissions that have overwhelmed its engineering teams and open-source maintainers.

Program Suspension and Timeline

The program’s official guidelines now state that as of October 1, 2026, no further product vulnerability reports will be accepted through the OSS VRP. This decision stems from a sharp increase in automated filings, predominantly invalid, according to a company statement published on X.

Scope of the OSS VRP

The OSS VRP targets security flaws in Google’s open-source projects, including Go, Angular, and Protocol Buffers. Launched in 2022, the initiative compensates researchers for identifying and privately disclosing vulnerabilities in these codebases, as well as in repository configurations and supply chain components.

Submission and Processing Changes

Reports submitted prior to October 1 remain valid, while the company may still process product vulnerability reports via its Cloud VRP for specific Google Cloud repositories affecting cloud-based products. Google has indicated plans to revise the OSS VRP framework and provide a progress update by the first quarter of 2027.

Alternative Programs for Researchers

Until then, researchers are directed to alternative programs such as the Cloud VRP or the Patch Rewards Program, which offers compensation for security enhancements to Google’s open-source projects. The program’s scope encompasses design or implementation flaws in Google open-source software that result in product vulnerabilities significantly impacting user data confidentiality or integrity within software builds utilizing Google’s code.

According to a company statement published on X, the shift highlights growing challenges in distinguishing legitimate findings from automated noise in security disclosure processes.

Acceptance Criteria and Project Tiers

Acceptance criteria for reports vary based on the project’s tier and the vulnerability’s classification. The reward structure for product vulnerabilities across the program’s four project tiers—ranging from OT0 (Flagship) to OT3 (Low-priority)—remains unspecified in the updated guidelines.

Context and Industry Concerns

This move follows prolonged concerns from open-source maintainers and bug bounty platforms regarding the surge of subpar, AI-assisted vulnerability reports, as previously reported by cybersecurity outlets. Researchers are advised to redirect submissions to active programs while Google addresses the backlog and restructures its open-source vulnerability management framework.



About Author

en_USEnglish