lupAI
seguranca

Google halts part of open source vulnerability reward program amid ai-generated false reports

GoogleSource: ITHome04/10/2026, 11:02
Google has suspended the acceptance of new vulnerability reports for its Open Source Software Vulnerability Reward Program (OSS VRP) starting October 1, 2026. This change does not affect reports submitted before that date. The company continues to accept reports for its Cloud Vulnerability Reward Program (Cloud VRP) if they pertain to Google Cloud products. According to Tom's Hardware, thousands of low-quality reports have overwhelmed Google's engineers and open-source maintainers. These reports, often generated by AI, claim to reveal critical vulnerabilities but are found to be false and non-exploitable. The burden of verifying these reports has diverted resources from addressing real security threats. Google stated it will restructure and optimize the OSS VRP and plans to share updates in the first quarter of 2027.
Google halts part of open source vulnerability reward program amid ai-generated false reports — lupAI