OSS VRP (Open Source Software Vulnerability Rewards Program) has temporarily been suspended after a sharp increase in automated reports that were found to be valid. Since October 1, security teams and open-source maintainers have been facing an increasing number of low-quality vulnerability reports generated via artificial intelligence.
The pause, which took effect on October 1, is in response to increasing volumes of low-quality vulnerability reports.
Google announced the OSS VRP in August 2022 as a means of rewarding researchers who identifies and responsibly discloses security flaws in open-source software maintained by the company.
The program covers projects such as Golang, Angular, Bazel, Protocol Buffers and Fuchsia, along with selected third-party dependencies. Security concerns regarding GitHub Actions, application configurations, repository settings, and access control rules are also covered by this program.
There was initially a range of rewards available from $100 to $31,337 under the program, with particular emphasis placed on vulnerabilities that could potentially pose significant risks for software suppliers.
As a result of the company's wider vulnerability rewards program, millions of dollars have since been awarded to researchers, making the OSS VRP an important means of identifying security vulnerabilities in widely used open-source projects.
An increase in automated submissions was responsible for the current suspension, according to the company, with the majority failing to identify valid security issues.
Although the use of artificial intelligence-assisted tools has made the generation of vulnerability reports at scale easier, the resulting volume may also include incorrect findings, duplicate claims, and reports concerning vulnerabilities that do not exist.
OSS VRP is currently being reviewed by Google to address the issue and determine how the program should handle the growing number of automated submissions.
A further update is anticipated in the first quarter of 2027. Additionally, the company clarifies that the change does not affect outstanding reports or product vulnerabilities submitted prior to October 1. The impact of the AI-driven reporting surge extends beyond Google's program as well.
It has not been the company's first time experiencing a sharp increase in low-quality vulnerability submissions that have been generated by automated tools. This raises concerns about the time security teams will need to spend validating reports that do not identify genuine vulnerabilities. The Google Patch Rewards Program continues to offer incentives to researchers for submitting high-impact open-source security patches that qualify for rewards of up to $15,000.
Google Cloud's Cloud Vulnerability Reward Program provides a means of reporting security vulnerabilities affecting open-source repositories related to Google Cloud products. Google's decision follows similar developments elsewhere in the security industry. In January, the curl project maintainer terminated its HackerOne bug bounty program in response to a significant number of low-quality, artificial intelligence-generated vulnerability reports.
As part of its Intigriti bug bounty program, Intel also removed financial rewards in September, though the company did not provide a publicly stated reason for the change. As the use of artificial intelligence tools increases in speed, potential vulnerabilities are identified and reported more rapidly, while the review process remains the responsibility of security researchers and maintainers.
Earlier this year, Microsoft warned that AI-assisted vulnerability discovery could increase the number and scale of security discoveries, potentially increasing the operational demands on security teams. Google has not yet confirmed that the Open Source OSS VRP will be permanently discontinued. The company is reviewing the program and anticipates making changes in the first quarter of 2027.
For now, the temporary suspension reflects a growing challenge for bug bounty programs, namely, how to handle a large volume of automated reports without allowing invalid findings to overwhelm genuine security issues.
The decision of Google highlights the difficulty of vulnerability reward programs as AI-assisted security research increases submissions. It will become increasingly important for these programs to distinguish genuine findings from automated and inaccurate reports in order for them to be effective.
