Google Froze Its Open Source Bug Bounty Program Due to a 'Significant Rise' in AI Submissions
16 Articles
16 Articles
Google has temporarily suspended accepting new product vulnerability reports under its OSS VRP rewards program. The reason is a sharp increase in automatically generated reports, with the company stating that the vast majority of them are invalid. The suspension applies to reports submitted after October 1, 2026. “We are temporarily no longer accepting product vulnerability reports under the OSS VRP,” the Google VRP team said in a post on the so…
Google Freezes Open Source Bug Bounty Program Due To Flood Of AI Submissions
Beyond restricting which Gemini models free and AI Plus users can use, Google has also announced that it is hitting pause on the Open Source Software Vulnerability Reward Program (OSS VRP). It’s only this specific bug bounty program that’s being paused, as the internet search giant still recommends bug bounty hunters contribute to other programs, […]
Google has announced that its "Google Open Source Software Vulnerability Reward Program (Google OSS VRP)," a bug bounty program for open-source software, will no longer accept product vulnerability reports after October 1, 2026. Read more...
Google has completely suspended its Open Source Software Vulnerability Reward Program (OSS VRP) as of October 1, citing a surge in fake bug reports automatically generated by AI. Google directly stated in posts on X (formerly Twitter) and the program's official website that "the number of automated submissions has increased significantly, and the majority of them are invalid." The suspension took effect on October 1. The OSS VRP is a specializ…
Coverage Details
Bias Distribution
- 34% of the sources lean Left, 33% of the sources are Center, 33% of the sources lean Right
Factuality
To view factuality data please Upgrade to Premium













