Skip to content

Google Pauses Bug Bounty Program Over Flood of Useless AI Reports

Google Pauses Bug Bounty Program Over Flood of Useless AI Reports

Google pauses paying bug hunters through its open-source rewards program, the OSS VRP. The reason is that automated reports are flooding in faster than its people can read them. And according to Google, most of them are garbage, full of bogus claims and made-up vulnerabilities.

Google created the OSS VRP to encourage skilled researchers to report vulnerabilities in its open-source projects. Researchers receive payment for their findings, and Google gains more secure code in projects such as Go, Angular, and Fuchsia.

Vibe coding changed things. The Google Bug Hunters team recently said the OSS VRP is no longer accepting product vulnerability submissions. The pause comes after a large increase in automated reports, which put heavy pressure on reviewers. Most of these vibe-coded reports are also of little use.

Google has also revised the OSS VRP rules to say it will not accept new vulnerability reports filed after October 1. Reports submitted before that date are still being processed. Some Google Cloud repositories may continue to take new submissions, but the main program is being restructured to deal with the disorder vibe coding has brought to open source. Google says it will announce the program’s future in the first quarter of 2027.

Google is making an exception for supply chain reports, which can affect far more systems than simpler bugs. Reports about especially serious flaws will also still be accepted. Researchers looking for rewards are being directed to Google’s other VRPs that remain open and to the Patch Rewards Program.

Google is not the only one affected. Vibe coding is reaching open-source projects that accept public contributions. Microsoft Edge, Linux, and other large FOSS projects face the same issues, while some smaller teams have stopped accepting AI-generated contributions to avoid being swamped by low-quality work. More broadly, many open-source projects find the volume of contributions too high to manage if they want to keep a proper vetting process.

Maybe you would like other interesting articles?

Leave a Reply

Your email address will not be published. Required fields are marked *