Google freezes submissions to OSS Vulnerability Reward Program after flood of bogus AI reports, update slated for Q1 2027
google open-source
| Source: Techmeme | Original article
Google has halted submissions to its Open‑Source Software Vulnerability Reward Program after a surge of low‑quality AI‑generated reports, and aims to roll out an update by Q1 2027.
Google has halted new product‑flaw submissions to its Open‑Source Software (OSS) Vulnerability Reward Program after a surge of low‑quality, AI‑generated reports overwhelmed engineers and open‑source maintainers. The influx, described by sources as “thousands of sloppy reports,” forced the company to temporarily freeze the intake of new findings while it reassesses the program’s triage process.
The episode highlights a growing tension between the efficiency gains promised by AI‑assisted security tooling and the practical challenges of filtering noise at scale. Automated scanners can churn out large volumes of potential vulnerabilities, but when the output lacks rigor, it creates a burden for human reviewers who must validate each claim. For Google, the bottleneck threatens the credibility of its bounty ecosystem and could delay the patching of genuine flaws in widely used open‑source components.
Google has announced that it will roll out an updated submission and verification workflow by the first quarter of 2027. The planned changes are expected to incorporate stronger signal‑to‑noise filters, clearer reporting guidelines, and possibly a tiered review system that separates AI‑suggested findings from manually vetted ones.
Stakeholders should watch for the detailed specifications of the new process when Google publishes them later this year, as well as any broader industry response. If other bounty platforms adopt similar safeguards, the episode could set a precedent for how AI‑driven security research is managed across the open‑source ecosystem.
Sources
Back to AIPULSEN