Google Tightens Open-Source Bug Bounty Rules After Surge in AI-Generated Vulnerability Reports
Google paused new OSS VRP product-vulnerability reports after a surge of invalid AI-generated submissions.
Google stopped accepting new product-vulnerability reports in its Open Source Software Vulnerability Reward Program on October 1, 2026, after a surge of mostly invalid automated and AI-assisted submissions. Reports filed before that date continue through normal triage, and OSS supply-chain compromise reporting remains open. Researchers are directed to Google Cloud VRP, Google AI VRP, or the Patch Rewards Program depending on impact. Google said it will update this part of the program in the first quarter of 2027.
48