· · Single source ·Updated

Google pauses open source bug bounty program due to AI submissions

Google has suspended its Open Source Software Vulnerability Rewards Program effective October 1 because of a significant increase in automated and invalid reports.

Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
File photo Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions Photo: TechCrunch

Reason for the pause

The company stated that the vast majority of recent submissions were not valid. Engineers and maintainers reported being overwhelmed by these low-quality entries. Many of the automated reports contained hallucinations rather than genuine security flaws.

Timeline for resumption

Google promised to provide an update regarding the program in the first quarter of 2027. Participants are currently encouraged to consider other bug bounty programs offered by the company. The suspension remains in place until further notice from the organization.

Reported by one outlet

Only one outlet has published this. Nothing here has been checked against a second report, so read it as that outlet's account and follow the link below for the original.

Reported by

1 independent outlet. Headline as published. Links open the original report.