Google Pauses Open Source Bug Bounty Over Invalid AI Submissions
Google halted its Open Source Software Vulnerability Rewards Program on October 1, citing a surge in automated reports that were mostly invalid, and says an update is due in Q1 2027.
Google has paused its Open Source Software Vulnerability Rewards Program as of October 1, the company said, after a significant rise in automated submissions that were, in the vast majority of cases, not valid.
According to TechCrunch, Google said it will provide an update on the program in the first quarter of 2027. In the meantime, the company encouraged participants to consider its other bug bounty programs.
The program had been open to researchers who reported security flaws in open source projects. Google did not give a date for when the pause might be lifted beyond the planned first-quarter update.
As of the pause, no details were given on how many submissions triggered the change or which reports were affected.
Background
Last year, TechCrunch reported that cybersecurity experts were warning that AI slop posed a serious risk to bug bounty programs. According to Tom's Hardware, Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations.
Quick answers
When did Google pause its Open Source Software Vulnerability Rewards Program?
The pause took effect on October 1, according to Google.
Why did Google pause the program?
Google cited a significant rise in automated submissions, the vast majority of which are not valid.
When will Google give an update on the program?
Google said it will provide an update in the first quarter of 2027.