Google suspends open source bug bounty program amid surge in AI-generated reports
Google has halted its Open Source Software Vulnerability Rewards Program until next year, citing a sharp increase in automated, largely invalid AI submissions.
Google announced that its Open Source Software Vulnerability Rewards Program will remain suspended through next year, with a promised status report in early 2027. The pause, which began on October 1, responds to a marked rise in AI-driven submissions that engineers and open source maintainers found to be largely invalid or fabricated. Internal statements highlighted that most of the recent entries were automated and did not meet the program's standards.
As a result, participants are encouraged to shift their efforts to Google's other bug bounty offerings. The move follows earlier warnings from cybersecurity experts about the risks AI-generated noise poses to bounty schemes. Google aims to reassess the program's structure before reinstating it.
Why it matters
The suspension highlights challenges AI tools create for security research and may affect how vulnerabilities are reported.
In this story
