Google pauses open-source bug bounty as AI hallucination reports overwhelm maintainers
10/04/2026 — 10/04, 17:15·1 sources·1 reports
Story overview
Google has stopped accepting product vulnerability submissions through its Open Source Software Vulnerability Reward Program (OSS VRP), effective October 1, 2026. The change was reported by Chinese tech outlet IT之家 on October 4, 2026. According to the report, product vulnerabilities submitted before October 1, 2026, will not be affected, and vulnerabilities that may impact Google Cloud products through Google Cloud code repositories may still be accepted through the Cloud VRP.
OSS VRP is a dedicated security bounty program Google established to encourage independent security researchers to find and responsibly disclose security flaws across the company's open source ecosystem. Citing Tom's Hardware, the report says people familiar with the matter revealed that Google engineers and open source code maintainers had been overwhelmed by thousands of low-quality reports. These reports claimed to have discovered severe vulnerabilities, but upon deeper investigation, they turned out to be AI-generated “hallucinations” — invalid and impossible to exploit. The maintenance team had to spend significant effort verifying this false code, which severely cut into the time available for fixing real, high-severity vulnerabilities.
The rule change took effect on October 1, 2026. OSS VRP is no longer accepting new product vulnerability submissions. Previously submitted reports remain unaffected, and Google Cloud-related vulnerabilities may still be reported through the Cloud VRP.
AI-generated from 1 reports · updated 1 hour ago
Latest turnGoogle says its Open Source Software Vulnerability Reward Program stopped accepting product vulnerability reports on October 1, 2026, with earlier submissions unaffected and Google Cloud repositories still covered by the Cloud VRP. According to Tom's Hardware, maintainers were overwhelmed by thousands of invalid AI-hallucinated reports, leaving less time to fix real high-severity bugs.
Reports on this story headlines open the original
Google says its Open Source Software Vulnerability Reward Program stopped accepting product vulnerability reports on October 1, 2026, with earlier submissions unaffected and Google Cloud repositories still covered by the Cloud VRP. According to Tom's Hardware, maintainers were overwhelmed by thousands of invalid AI-hallucinated reports, leaving less time to fix real high-severity bugs.
IT之家AI score 67
Other stories people are talking about
- 383RisingGoogle limits free Gemini users to Flash-Lite starting October 96 sources
- 347Apple tightens macOS Full Disk Access over AI agent risks9 sources
- 246NVIDIA launches 64GB DGX Spark desktop AI computer at $4,9998 sources
- 236Meta open-sources Muse Gadgets firmware and SDK6 sources
- 190OpenAI safety staffer David Robinson resigns and warns in The Atlantic3 sources
- 182Claude Opus 5.5 and GPT-6 Sol: comparing cost per task4 sources
How is heat calculated?About the methodHide
Heat counts how many independent sources covered a story in the last 48 hours: one source counts once no matter how many posts it published, decaying with a 24-hour half-life. What ranks first is what many people are talking about.
This page aggregates public feeds. Headlines and summaries are machine-organized and remain the property of the original authors; verify important facts at the source.
- Surge
- Discussion rising fast
- New
- First report within 6 hours
- Rising
- Still gathering discussion
