Build5 publishers2 min readPublished
Google halts product reports to its open-source bug bounty after a flood of invalid AI submissions
Google stopped taking product vulnerability reports for its open-source bug bounty on October 1 after a flood of invalid AI-generated submissions. Any team that takes outside security reports faces the same imbalance, with reports now cheap to write and as costly as ever to check.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Google said it will update the program's status by the first quarter of 2027 and pointed researchers to its other vulnerability reward programs.
- Linux maintainers said they were "completely overwhelmed" after AI-powered bug hunters pushed the kernel to a record 2,000 vulnerabilities per release.
- Tom's Hardware reports that Linux also ended support for older network drivers because of an influx of false AI-generated bug reports.
- Intel suspended a bug bounty that paid up to $100,000 per flaw, though the company has not confirmed AI-generated reports as the reason.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- exposure Genuine flaws in Google's public repositories lose their paid reporting route for up to six months unless they count as supply chain issues or fall under the Cloud VRP.
- contradiction Mezha, citing TechCrunch, describes the whole program as paused, while Tom's Hardware says supply chain reports still go through, so a researcher reading only the first account would wrongly assume every channel is shut.
- constraint With Intel's bounty and Google's product category both suspended, researchers who still find bugs by hand have fewer paid places to report them.
The OSS VRP rewards independent researchers who find and disclose flaws across Google's open-source ecosystem. Its product category covers code defects, logic flaws and design bugs in Google's public repositories [4]. Tom's Hardware describes that work as painstaking and manual, something that used to take skill, and says large language models and automated bug-hunting scripts have nearly removed its cost [5]. Checking a report is still done by hand [7]. Google engineers and maintainers were reportedly swamped by thousands of reports describing bugs that turned out to be invalid or unexploitable hallucinations [6]. They spent their time validating code by hand instead of fixing real, critical vulnerabilities [7]. Mezha, citing TechCrunch, wrote that most of the AI-assisted submissions were invalid [8]. It added that reviewers could not keep up with reports built on false data and invented facts [9].
The cut is narrow, and I think it is well made. According to Tom's Hardware, product reports filed before October 1 are still in scope [10]. Supply chain reports to the same program continue [11]. Google also said it may still accept product reports through the Cloud VRP "for some Google Cloud repos impacting Google Cloud products" [12]. I would shed load on an overloaded queue the same way: stop the category that is failing and keep reading the work already filed. Google posted the change on X the day it took effect, so researchers with a report half-written on September 30 got no grace period [1][10].
Google's experience carries over to a smaller program under two conditions. The intake has to draw the same automated volume, and each report has to need a person to validate it by hand [7]. I'd expect the second condition to hold for any project whose reviewers reproduce bugs themselves. The first is harder to judge from outside. Neither report gives Google's invalid-report rate or its review time per report. A team would need both figures to size a triage budget, and the reporting stops at "thousands" and "most" [6][8].
What to watch
- Google's first-quarter 2027 update, and whether product submissions reopen with new conditions on who can submit or what evidence a report must carry.
- Whether Intel states a reason for suspending its bounty of up to $100,000 per flaw.
- Whether Google publishes how many OSS VRP submissions were invalid; other programs could size their own triage from that rate.