Google has suspended its open-source bug bounty program, known as OSS VRP, in response to a flood of invalid reports generated with artificial intelligence. The freeze took effect on October 1, the same day the company announced it, and it does not apply to product vulnerabilities that were submitted before that date. Google indicated it may still accept certain reports covering product vulnerabilities through the Cloud VRP.

The Cloud VRP exception covers some Google Cloud repos that impact Google Cloud products, according to Google. The suspension also leaves OSS VRP supply chain reports unaffected. OSS VRP is a specialized Google security bounty program that pays independent researchers to find and responsibly disclose security flaws across Google's open-source ecosystem.

Under the program, product vulnerability submissions focus on code defects, logic flaws, or design bugs within Google's public repositories. That work was usually painstaking and manual, and it required skill. The rise of large language models and automated AI bug-hunting scripts has nearly removed the cost and effort the task once demanded, leading to an influx of low-effort, AI-generated bug reports.

Google engineers and open-source maintainers were reportedly overwhelmed by thousands of these poorly written reports. The submissions claimed to find bugs but were actually completely invalid or unexploitable hallucinations. The engineers and maintainers ended up spending too much time manually validating code instead of fixing real, critical vulnerabilities. That is what led to the suspension of the program.

Similar scenarios have been playing out across the industry. Earlier this month, Linux maintainers said they were completely overwhelmed by CVE finds after AI-powered bug hunters pushed the Linux kernel to a record 2,000 vulnerabilities per release. Linux also ended support for older network drivers because of an influx of false AI-generated bug reports, a similar case to Google's.

Intel also suspended its bug bounty program, which paid up to $100,000 per flaw. The company did not officially confirm AI-generated reports as the reason for the move, but experts suspect this is the case.

More software news from TechManNews.