Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Google Reworks Open-Source Security Program After Surge in AI-Generated Bug Reports

Google Reworks Open-Source Security Program After Surge in AI-Generated Bug Reports

By: Morgan Cipher — Senior Privacy Journalist

Last updated: October 6, 2026

Human Written
Google Reworks Open-Source Security Program After Surge in AI-Generated Bug Reports
  • Google has paused new product vulnerability submissions to its OSS VRP after a surge in low-quality automated reports.

  • Researchers can still use Google’s Patch Rewards Program, Cloud VRP, and other security reporting channels.

  • Google plans to revise the OSS VRP and provide another update during the first quarter of next year.

Google has put a halt on accepting incident reports as part of the Open Source Software Vulnerability Rewards Program (OSS VRP). This decision came due to a surge in automated reports that do not point out valid security flaws.

The OSS VRP rewards researchers who find flaws in the open-source projects of Google. However, the company now wants to adjust the program after AI-generated reports created a heavier review workload for its security teams.

Google Faces a Wave of Automated Security Reports

The tech giant launched the OSS VRP in 2022, which aims to make open-source software safer for its ecosystem. This protection includes projects such as Golang, Angular, Bazel, Protocol Buffers, and Fuchsia. Also, it extends to some essential third-party components and vulnerabilities related to repository setups, including GitHub Actions, application configurations, plus access control rights.

In the beginning, the program offered from $100 and up to $31,337 in rewards. Google designed those rewards to encourage researchers to find flaws with serious effects on the software supply chain. However, the company now faces a different challenge. AI tools can produce vulnerability reports at a much faster rate than human researchers.

Google says most recent automated submissions did not contain valid security findings. Some alerts can register real issues in the code but have no significant impact in terms of security. This became a problem in itself since it requires the work of security teams and takes time during the screening of the alerts.

Google has already changed its OSS VRP rules to address this trend. Earlier updates introduced stricter evidence requirements for certain vulnerability categories.

AI is Changing How Researchers Find Vulnerabilities

AI has changed the speed and scale of security research. It provides various tools for examination of source code & description of problems with it. Also, it suggests the appropriate solutions plus shows possible paths of attack. However, if the method is quick, that does not ensure success.

AI agents are also moving beyond vulnerability research into offensive activity, with autonomous AI agents deploying custom ransomware to target AI models, detailing how an autonomous agent was used to deploy ransomware against AI systems. For example, an AI system may produce a very convincing report, but will not demonstrate whether it is possible for an attacker to exploit the vulnerability.

Google highlighted this problem in its earlier OSS VRP updates. The company noted a rise in reports containing incorrect details or unrealistic vulnerability scenarios. Some submissions also pointed to coding errors with little practical security impact.

For example, a report might identify a buffer overflow but fail to show that attackers can reach the affected code. Thus, Google now aims for stronger proof from researchers, i.e., reliable reproduction of steps, OSS-Fuzz results, or a merged patch.

The company has created the related project tiers in order to distinguish the high-importance open-source projects from the less crucial ones. This approach helps its teams focus on vulnerabilities that could create greater real-world damage.

The wider bug bounty programs of Google show the same shift. The company increasingly values clear evidence and demonstrated impact instead of long technical reports alone.

Researchers Still Have Other Google Programs

The pause does not close every path for security researchers who want to work with Google. Researchers can still report issues through several other vulnerability reward programs. The Patch Rewards Program of Google remains available for researchers who create security improvements for open-source software. The company also continues to accept relevant vulnerabilities through its Cloud VRP.

The OSS VRP itself also continues to cover certain supply chain security issues. Google says those reports remain important because attackers can use compromised build systems or source repositories to affect many users. In addition, credential leaks remain a priority under the program. Exposed credentials with write access can create serious risks for open-source projects and their users.

Google has not abandoned its broader bug bounty strategy. Instead, the company appears to be changing how it handles the growing volume of automated security research. That change follows a wider industry concern. AI helps make the process easier for researchers as it helps identify vulnerabilities, but it also produces thousands of weak & false reports.

For security teams, that creates a new balancing problem. They must gain the benefits of AI without allowing low-quality submissions to overwhelm human analysts.

Google Plans Further Changes to the OSS VRP

Google says it plans to rework the OSS VRP and provide more details about the next changes. The company expects to give another update during the first quarter of 2027. The current pause affects product vulnerability submissions made from October 1 this year. Existing reports and supply chain reports remain outside the scope of the suspension.

The decision of Google also comes after years of major spending on vulnerability research. Its bug bounty programs have rewarded thousands of researchers since the company launched its first VRP in 2010.

The security program of the company records shows more than $81.9 million in total rewards. Researchers received over $17 million in 2025 alone. Therefore, the company still believes that external researchers are a crucial element of security for its systems. The challenge now involves separating useful research from automated noise.

Meanwhile, Google continues to adjust other VRPs for the AI era. Its Android and Chrome programs have also moved toward stronger proof of real security impact. The latest OSS VRP suspension shows how rapidly AI has developed in vulnerability research. It hints that in the future, bug bounty programs will give priority to verification, evidence of exploitation, and meaningfully applicable solutions.

Share this article

You might also like

Denmark Says 8.8 Million Records Exposed in CPR Data Breach

Denmark’s National Population Register Breach Exposes Data on 8.8 Million People

Unknown attackers misused a private company’s legal access to Denmark’s CPR database. The breach exposed names, home addresses, and CPR…

October 6, 2026
Hacker Claims Access to India’s CAG Website is for Sale for $300

India’s National Audit Website Faces $300 Dark Web Access Claim

A hacker using the name 0x4ziz claims to have broken into India’s CAG website and is selling access for $300.…

October 4, 2026
Hacker Claims Baltaş Eksen Breach Exposed Data From 750 Turkish Companies

Turkish HR Provider Baltaş Eksen Faces 750-Company Data Exposure Claim

A hacker claims he stole data from more than 750 Turkish companies and put it up for sale. The claim…

October 4, 2026

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.