AI News Feed
Market watch
Companies

Google Pauses Open Source Bug Bounty Program, Citing Surge in AI Submissions

Google has paused its Open Source Software Vulnerability Rewards Program since October 1 after a significant rise in automated AI submissions, most of which it says are invalid. The company expects to provide an update in the first quarter of 2027.

The program had rewarded researchers for finding vulnerabilities in Google's open source software. In posts on X and on the program's website, Google said the pause was necessary because of the surge in automated submissions. It encouraged participants to consider its other bug bounty programs while the open source program is suspended.

Google attributed the problem to a "significant rise" in AI submissions. TechCrunch reported last year that cybersecurity experts were warning that AI slop posed a serious risk to bug bounty programs. According to Tom's Hardware, Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations.

"This pause is due to a significant rise in automated submissions, the vast majority of which are not valid," Google said.

The pause leaves a gap for researchers who used the Open Source Software Vulnerability Rewards Program to report bugs in Google's open source projects. Google did not say how long the review would last beyond the first-quarter 2027 update. It also did not detail changes that might be made before submissions reopen. Participants were directed to Google's other bug bounty programs in the meantime.

Editor's Summary Google paused its Open Source Software Vulnerability Rewards Program on October 1, citing a significant rise in automated submissions that were largely invalid. The company expects to provide an update in the first quarter of 2027 and is directing researchers to its other bug bounty programs. The move follows warnings that AI-generated reports could overwhelm vulnerability reward systems.