International Edition
Latest News
Technology

Google Suspends Open Source Vulnerability Program Over AI Submissions

Google Suspends Open Source Vulnerability Program Over Invalid AI Submissions Google has temporarily suspended its open source software vulnerability reporting programme until at least the start of 2027, citing an overwhelming volume of invalid AI-generated bug reports. The…

Google Suspends Open Source Vulnerability Program Over AI Submissions

Google Suspends Open Source Vulnerability Program Over Invalid AI Submissions

Google has temporarily suspended its open source software vulnerability reporting programme until at least the start of 2027, citing an overwhelming volume of invalid AI-generated bug reports. The four-year-old OSS VRP supports vulnerability discovery across open-source software stored in repositories run by Google-owned GitHub organisations, alongside selected repositories hosted elsewhere. The scheme also covers configuration settings such as GitHub actions, access control rules, and application configurations, historically including vulnerabilities in third-party dependencies. Payouts range from $500 for security issues in projects classed as Important to over $30,000 for supply chain compromises in Flagship projects.

Google Halts Submissions Through Q1 2027

Google announced the temporary freeze through a statement posted on the social media platform X, explaining that the platform is no longer accepting product vulnerability submissions under the OSS VRP. Supply chain reports and outstanding submissions remain unaffected by the pause.

“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” Google stated. The company committed to reformatting and working on this aspect of the OSS VRP, promising a formal update in the first quarter of 2027. Researchers seeking alternatives are encouraged to submit findings through Google’s other VRP programmes or pursue the Patch Rewards Program.

Threat Intelligence Group Findings on AI-Assisted Discovery

A September 2026 study conducted by Google’s Threat Intelligence Group (GTIG) revealed that the total number of vulnerabilities disclosed per month doubled over the course of the year, rising from 5,045 in January to 10,740 in August. Exploited vulnerabilities in the wild also increased from a monthly average of 10.5 in 2025 to 18 per month in 2026.

GTIG researchers found that AI-assisted discovery unearths proportionally fewer low-risk flaws, more moderate-risk flaws, and an increased volume of flaws leading to remote code execution. Publicly available data likely undercounts these figures because common vulnerability and exposure repositories lack uniform metadata tags for AI attribution, and cloud providers frequently patch AI-surfaced flaws directly in production without requesting formal CVE identifiers.

Frequently Asked Questions About the OSS VRP Suspension

Which Google vulnerability programmes remain active?

Google’s supply chain reports and any outstanding reports already submitted to the OSS VRP are unaffected by the suspension. The company also encourages researchers to submit findings to its alternative vulnerability reward programmes or pursue the Patch Rewards Program.

What financial payouts were previously offered under the scheme?

Payments ranged from $500 for security issues in Important open-source projects up to more than $30,000 for supply chain compromises identified in Flagship projects.

Google pauses open source bug bounty as AI submissions flood in | Daily Tech Brief · Oct 5

What changes did GTIG observe in vulnerability exploitation trends?

GTIG noted that vulnerabilities exploited in the wild rose from an average of 10.5 per month in 2025 to 18 per month in 2026, alongside an overall monthly disclosure rise from 5,045 in January to 10,740 in August.

About the author: Anika Shah - Technology

MSc in Computer Science, senior reporter. Anika focuses on AI ethics, cybersecurity, and emerging hardware—frequently moderating panels at CES and Web Summit. “Anika Shah decodes tech breakthroughs and startup disruption shaping tomorrow’s digital landscape.”