Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
Summary
Google has paused its Open Source Software Vulnerability Rewards Program until at least the first quarter of 2027, citing a “significant rise” in automated submissions, the vast majority of which were invalid or contained hallucinations. The program rewarded researchers for finding vulnerabilities in Google's open source software. According to Tom's Hardware, Google engineers and open source maintainers were overwhelmed by the flood of low-quality reports. This development follows earlier warnings from cybersecurity experts that AI slop posed a serious risk to bug bounty programs. During the pause, participants are encouraged to consider Google's other bug bounty programs. The company promised to provide an update in the first quarter of 2027.
(Source:TechCrunch)