MalwareTips News Google halts open-source bug reports as automated submissions surge

Have you ever submitted a security bug to a vulnerability reward program?

  • Yes, successfully

    Votes: 0 0.0%
  • Yes, but it was rejected

    Votes: 0 0.0%
  • No, but I might

    Votes: 0 0.0%
  • No, and I do not plan to

    Votes: 0 0.0%
  • I am not sure

    Votes: 0 0.0%

  • Total voters
    0

News Now

Happening Now
Verified
MalwareTips-news-165.jpg

Image: Malwarebytes Labs

Google has temporarily stopped accepting reports through its Open Source Software Vulnerability Rewards Program after a sharp increase in automated submissions. The pause matters mainly to security researchers and open-source maintainers; everyday users do not need to change any Google security settings.


Most automated reports were invalid​

Malwarebytes Labs reports that Google paused OSS VRP because automated reports had risen significantly and the vast majority were invalid. Bug bounty programs reward outside researchers for responsibly reporting security flaws.

Generative AI can quickly produce polished-looking reports, but each claim may still require a person to prove or disprove it. Invalid and duplicate submissions can therefore consume time that engineers and maintainers could spend fixing confirmed problems.

  • Google has not announced the design of a replacement submission process.
  • The company has promised an update in the first quarter of 2027.

A wider problem for bounty programs​

Google is not alone. Curl ended its HackerOne bounty program in early 2026 after low-quality reports, often generated with AI, overwhelmed its small security team.

Intel also launched a program on Intigriti but reportedly removed its available bounties to curb a flood of AI-generated reports. These cases show how cheaper report generation can place a much larger review burden on security teams.

What legitimate researchers can do​

Researchers should retain reproducible steps, a working proof of concept and clear evidence of impact while submissions are closed. AI-assisted findings can still be valid, but validation, duplicate checking and proof are essential.

Google could eventually add stronger evidence requirements or rate limits, but those ideas have not been confirmed. Until the promised update, details of any redesigned program remain speculative.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top