AI slop submissions force Google to freeze its open-source bug bounty – Help Net Security

AI slop submissions force Google to freeze its open-source bug bounty – Help Net Security
Google has stopped accepting new product vulnerability reports through its Open Source Software Vulnerability Reward Program after a surge of automated, AI-generated submissions overwhelmed reviewers. Reports submitted before October 1 remain valid, and researchers are being redirected to other reward programs while Google plans an update in Q1 2027. #Google #OSSVRP #CloudVRP #PatchRewardsProgram

Keypoints

  • Google paused new product vulnerability reports in its OSS VRP.
  • The change was driven by a flood of invalid, AI-generated submissions.
  • Reports submitted before October 1 are still accepted.
  • Some Google Cloud repository issues may still be reported through Cloud VRP.
  • Google plans to provide a program update in Q1 2027.

Read More: https://www.helpnetsecurity.com/2026/10/05/google-ai-generated-vulnerability-reports-pause/