Google has paused its open-source vulnerability reward program while it works on changes to address a surge in low-quality, AI-generated bug reports, according to reporting published October 5. The company said the change does not affect product vulnerabilities submitted before October 1 and directed researchers toward other eligible programs and Patch Rewards in the interim.

The episode illustrates a growing strain on vulnerability-disclosure operations: automated or AI-assisted submissions can increase volume without increasing validated security findings. For open-source maintainers and security teams, that means triage capacity, reproducibility requirements, and clear reporter guidance are becoming even more important.

Researchers should continue to follow each program’s current scope and submission rules, provide a minimal reproducible proof of concept where appropriate, and avoid filing issues whose impact has not been established. Organizations operating their own disclosure programs can use this moment to review rate limits, duplicate detection, and the evidence required before an item enters engineering queues.

Source: BleepingComputer.

By Allan