Google froze its open supply bug bounty program on account of a ‘vital rise’ in AI submissions

Blaming a “vital rise” in AI submissions, Google has paused its open supply bug bounty program till subsequent 12 months.
Last 12 months, TechCrunch reported that cybersecurity experts were warning of that AI slop posed a serious risk to bug bounty programs. Looks like that’s the problem confronting Google’s Open Source Software Vulnerability Rewards Program, the place researchers had been rewarded for locating vulnerabilities within the firm’s open supply software program.
In posts on X and the program website, Google stated the bug bounty program was paused as of October 1, with a promise to offer “an replace” within the first quarter of 2027. According to Tom’s Hardware, Google engineers and open supply maintainers had been overwhelmed by reviews that had been invalid or contained hallucinations.
“This pause is because of a major rise in automated submissions, the overwhelming majority of which aren’t legitimate,” the corporate stated.
In the meantime, contributors are inspired to think about Google’s different bug bounty applications.
