search
Google Bug Bounty Program
Trends
- 1Google pauses open-source bug bounty program after flood of invalid AI-generated reportsβGoogle freezes open-source bug bounty program amid flood of invalid AI slop submissions β product flaw submissions halted until 2027 as maintainers drown in hallucinations
Google has suspended submissions to its open-source bug bounty program until 2027, according to Tom's Hardware, after a surge of low-quality, AI-generated bug reports overwhelmed engineers and maintainers. The reports, often plausible-sounding but fabricated or hallucinated flaws, have made it impractical to separate genuine vulnerabilities from noise, prompting the freeze on new product flaw submissions.
- 2Google freezes open-source bug bounty program amid AI slopβGoogle freezes open-source bug bounty program amid flood of invalid AI slop
Google has suspended part of its open-source Vulnerability Reward Program, ending rewards for product vulnerability submissions as of October 1. The move comes after a flood of invalid, low-quality reports generated with AI tools overwhelmed the program. Security researchers and developers are debating how automated junk reports are undermining traditional bug bounty systems and what it means for open-source security funding going forward.
- 3Google pauses open source bug bounty amid AI-generated reportsβGoogle pauses open source bug bounty program after rise in AI submissions
Google has suspended its open source bug bounty program following a surge in AI-generated submissions. The company says automated tools are flooding the program with low-quality vulnerability reports, overwhelming reviewers and making it harder to identify genuine security issues. The move has sparked debate among security researchers about the impact of AI on bug bounty ecosystems.
- 4Google Narrows Open Source Bug Bounty Amid Flood of Invalid ReportsβGoogle Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports
Google is restricting its bug bounty program covering open source projects after a surge of low-quality, automated vulnerability reports flooded its review process. The company says AI-generated submissions, many invalid or low-value, have overwhelmed security teams, forcing it to narrow eligibility and tighten criteria for rewards. Security researchers are debating the move, with some warning that legitimate findings may now be overlooked as programs tighten rules across the industry.
- 5Google pauses open-source bug bounty amid AI report floodβGoogle pauses its open-source bug bounty program after a flood of AI slop reports
Google has paused its open-source bug bounty program after receiving a flood of low-quality, AI-generated vulnerability reports. The influx of automated or copy-paste submissions has overwhelmed reviewers and made the program impractical to run. The move highlights a growing problem for bug bounty platforms as generative AI makes it cheap to mass-produce plausible-looking but useless security reports, drowning out legitimate findings from real researchers.
- 6Google Suspends Open-Source Bug Bounty Over AI Vulnerability ReportsβGoogle Suspends Open-Source Bug Bounty Due to AI Vulnerability Reports
Google has suspended its open-source bug bounty program, citing a flood of AI-generated vulnerability reports. The company says automated tools are producing low-quality submissions that overwhelm reviewers, making the program unsustainable in its current form. Security researchers are debating what this means for legitimate disclosure and the growing noise from AI-assisted bug hunting across the industry.
- 7Google pauses open source bug bounty amid flood of AI reportsβGoogle benches open source bug bounty program following βsignificant riseβ in AI submissions
Google has suspended its open source bug bounty program, citing a significant rise in AI-generated vulnerability submissions. The company says many of the reports flooding in are low-quality, machine-written findings that take up valuable reviewer time without adding real security value. The move has sparked debate among security researchers about the impact of automated tools on responsible disclosure programs and how bounty platforms should handle AI-created noise.
- 8
Google has paused its open source bug bounty program, citing a surge of submissions generated by AI tools. Low-quality automated reports are reportedly overwhelming reviewers, prompting the company to halt new submissions while it reassesses how to handle the influx. Security researchers are watching closely, as the decision raises broader concerns about AI-generated spam affecting vulnerability disclosure programs.
- 9Google pauses open source bug bounty over AI-generated reportsβGoogle pauses bug bounties for open source because AI slop reports are drowning its reviewers
Google has paused its bug bounty program for open source projects, citing a flood of low-quality, AI-generated vulnerability reports that is overwhelming its reviewers. The company says the volume of automated, often inaccurate submissions has made the program difficult to sustain, raising wider concerns about how AI is straining security research ecosystems.