search
Google Bug Bounty Program
Trends
- 1Google pauses open-source bug bounty amid flood of AI-generated invalid reports●Google freezes open-source bug bounty program amid flood of invalid AI slop
Google has suspended part of its open-source vulnerability reward program, ending submissions for product vulnerabilities as of October 1. The move follows a wave of low-quality, AI-generated bug reports that overwhelmed reviewers with invalid submissions. The decision has sparked discussion among security researchers about how automated AI tools are degrading traditional bug bounty programs and what platforms can do to filter out machine-generated noise.
- 2
Google has paused its open-source bug bounty program, with reports linking the decision to a flood of low-quality, AI-generated submissions. The program paid researchers for finding vulnerabilities in Google's open-source projects, and the influx of trivial or fabricated reports appears to have made it harder to identify genuine security flaws. Security watchers say the move highlights how generative AI tools are straining vulnerability disclosure programs across the industry.
- 3Google Halts Open Source Bug Bounties After AI-Generated Reports▼Google Halts Open Source Bug Bounties Following Deluge of AI Slop
Google has suspended its bug bounty program for open source projects, citing a flood of low-quality, AI-generated vulnerability reports. The company says automated submissions have become too noisy to process, overwhelming reviewers and crowding out legitimate security findings. The move has sparked debate among security researchers about AI's impact on vulnerability disclosure and whether programs will need stricter verification as machine-generated reports proliferate.