Tech Meridian ← LIVE FEED
PROMY MERIDIAN RU

NEWS · CODING · #1492

Google pauses Open Source Software Vulnerability Rewards Program after surge in AI submissions

Google paused its Open Source Software Vulnerability Rewards Program effective October 1, 2026, citing a "significant rise" in automated AI-generated submissions that were largely invalid or hallucinatory; the company said it will provide an update in Q1 2027 and encouraged researchers to use its other bug bounty programs. Reports said Google engineers and maintainers were overwhelmed by the volume and low quality of submissions.

KEY POINTS

  1. Google paused its Open Source Software Vulnerability Rewards Program effective October 1, 2026, citing a "significant rise" in automated AI-generated submissions that were largely invalid or hallucinatory; the company said it will provide an update in Q1 2027 and encouraged researchers to use its other bug bounty programs.
  2. Reports said Google engineers and maintainers were overwhelmed by the volume and low quality of submissions.
  3. This shows AI‑generated reports can materially disrupt security workflows and undermine open source vulnerability programs, forcing major vendors to change operations.

WHY IT MATTERS

This shows AI‑generated reports can materially disrupt security workflows and undermine open source vulnerability programs, forcing major vendors to change operations.

SOURCES & TIMELINE

1