HaiAI123

Curated Global AI Tools Directory

NewHot story
99
heat index
New

Google pauses open-source bug bounty as AI hallucination reports overwhelm maintainers

10/04/2026 — 10/04, 17:15·1 sources·1 reports

Story overview

Google has stopped accepting product vulnerability submissions through its Open Source Software Vulnerability Reward Program (OSS VRP), effective October 1, 2026. The change was reported by Chinese tech outlet IT之家 on October 4, 2026. According to the report, product vulnerabilities submitted before October 1, 2026, will not be affected, and vulnerabilities that may impact Google Cloud products through Google Cloud code repositories may still be accepted through the Cloud VRP.

OSS VRP is a dedicated security bounty program Google established to encourage independent security researchers to find and responsibly disclose security flaws across the company's open source ecosystem. Citing Tom's Hardware, the report says people familiar with the matter revealed that Google engineers and open source code maintainers had been overwhelmed by thousands of low-quality reports. These reports claimed to have discovered severe vulnerabilities, but upon deeper investigation, they turned out to be AI-generated “hallucinations” — invalid and impossible to exploit. The maintenance team had to spend significant effort verifying this false code, which severely cut into the time available for fixing real, high-severity vulnerabilities.

The rule change took effect on October 1, 2026. OSS VRP is no longer accepting new product vulnerability submissions. Previously submitted reports remain unaffected, and Google Cloud-related vulnerabilities may still be reported through the Cloud VRP.

AI-generated from 1 reports · updated 1 hour ago

Latest turnGoogle says its Open Source Software Vulnerability Reward Program stopped accepting product vulnerability reports on October 1, 2026, with earlier submissions unaffected and Google Cloud repositories still covered by the Cloud VRP. According to Tom's Hardware, maintainers were overwhelmed by thousands of invalid AI-hallucinated reports, leaving less time to fix real high-severity bugs.

Reports on this story headlines open the original

Today
  1. Google says its Open Source Software Vulnerability Reward Program stopped accepting product vulnerability reports on October 1, 2026, with earlier submissions unaffected and Google Cloud repositories still covered by the Cloud VRP. According to Tom's Hardware, maintainers were overwhelmed by thousands of invalid AI-hallucinated reports, leaving less time to fix real high-severity bugs.

    IT之家AI score 67

Other stories people are talking about

How is heat calculated?About the method

Heat counts how many independent sources covered a story in the last 48 hours: one source counts once no matter how many posts it published, decaying with a 24-hour half-life. What ranks first is what many people are talking about.

This page aggregates public feeds. Headlines and summaries are machine-organized and remain the property of the original authors; verify important facts at the source.

Surge
Discussion rising fast
New
First report within 6 hours
Rising
Still gathering discussion

Back to the hot board →