Google Suspends Open-Source Bug Bounty Due to AI Vulnerability Reports
Google paused its open-source bug bounty until 2027 after a surge of invalid AI-generated vulnerability reports.
Google said on October 1 that it is suspending the Open Source Vulnerability Rewards Program until 2027 because of a sharp rise in automated submissions, most of them invalid. OSS VRP, launched in August 2022, pays $100 to $31,337 for flaws in Google-owned open-source repositories and selected configuration settings. Supply-chain reports and reports already submitted continue. Google plans an update in the first quarter of 2027 and points researchers to its other reward programs or the Patch Rewards Program.
- OSS VRP paused until 2027 over mostly invalid automated reports
- Rewards had ranged from $100 to $31,337 by severity
- Supply-chain reports and existing submissions remain unaffected
- Google expects a reformatted program update in Q1 2027
Full article301 words · extracted from infosecurity-magazine.com · click to collapse
Google has suspended its open-source bug bounty program until 2027 in an effort to stem the flood of AI submissions.
In a statement posted on social media on October 1, Google said the pause was prompted by “a significant rise in automated submissions, the vast majority of which are not valid.”
Google OSS VRP: History and Scope
Google’s Open Source Vulnerability Rewards Program (OSS VRP) was launched in August 2022. It rewards security researchers for identifying vulnerabilities in Google’s open-source software projects.
The program covers the latest versions of open-source software hosted in public repositories owned by Google on GitHub, as well as selected repositories on other platforms.
It also includes repository configuration settings, such as GitHub Actions workflows, access control rules and GitHub application configurations.
Rewards range from $100 to $31,337 based on the severity level of the reported flaws and the project's importance.
The OSS VRP is one of several bug bounty programs operated by Google and has a relatively narrow focus.
Vulnerabilities in Google's open source projects that are closely linked to Google Cloud or AI products are directed to the Google Cloud Vulnerability Reward Program (Cloud VRP) or the AI Vulnerability Reward Program (AI VRP), allowing reports to be routed to the teams best placed to assess and address them.
Google Plans OSS VRP Overhaul
The suspension will not affect OSS VRP supply-chain reports or any reports already submitted, Google said.
The company plans to “reformat” the program and expects to provide an update in the first quarter of 2027.
“As an alternative, we encourage you to find impact across our other VRP programs and submit there instead, or pursue the Patch Rewards Program,” Google said.
Image credits: JHVEPhoto / Shutterstock.com
Read now: How Industry Coalitions Are Rallying to Secure Open Source Software for the AI Era
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/google-suspends-opensource-bug/