Google Suspends Open-Source Bug Bounty Due to AI Vulnerability Reports

Written by

Google has suspended its open-source bug bounty program until 2027 in an effort to stem the flood of AI submissions.

In a statement posted on social media on October 1, Google said the pause was prompted by “a significant rise in automated submissions, the vast majority of which are not valid.”

Google OSS VRP: History and Scope

Google’s Open Source Vulnerability Rewards Program (OSS VRP) was launched in August 2022. It rewards security researchers for identifying vulnerabilities in Google’s open-source software projects.

The program covers the latest versions of open-source software hosted in public repositories owned by Google on GitHub, as well as selected repositories on other platforms.

It also includes repository configuration settings, such as GitHub Actions workflows, access control rules and GitHub application configurations.

Rewards range from $100 to $31,337 based on the severity level of the reported flaws and the project's importance.

The OSS VRP is one of several bug bounty programs operated by Google and has a relatively narrow focus.

Vulnerabilities in Google's open source projects that are closely linked to Google Cloud or AI products are directed to the Google Cloud Vulnerability Reward Program (Cloud VRP) or the AI Vulnerability Reward Program (AI VRP), allowing reports to be routed to the teams best placed to assess and address them.

Google Plans OSS VRP Overhaul

The suspension will not affect OSS VRP supply-chain reports or any reports already submitted, Google said.

The company plans to “reformat” the program and expects to provide an update in the first quarter of 2027.

“As an alternative, we encourage you to find impact across our other VRP programs and submit there instead, or pursue the Patch Rewards Program,” Google said.

Image credits: JHVEPhoto / Shutterstock.com

Read now: How Industry Coalitions Are Rallying to Secure Open Source Software for the AI Era

What’s Hot on Infosecurity Magazine?