Yovao News · The World, In Focus. From Local to Global, Never Miss a Beat

Google Halts Open Source Bug Bounty Program Amid Surge of AI-Generated Reports

Google Halts Open Source Bug Bounty Program Amid Surge of AI-Generated Reports

Google has suspended its Open Source Software Vulnerability Rewards Program, citing a “significant rise” in automated submissions that are largely invalid. The pause, effective October 1, will remain in place until at least the first quarter of 2027, according to announcements posted on X and the program’s official website.

The decision follows concerns raised by cybersecurity experts last year about the growing threat of “AI slop”—low-quality or hallucinated bug reports generated by artificial intelligence tools—overwhelming security teams and diluting the value of vulnerability disclosures.

In a statement, Google explained that engineers and open source maintainers had been inundated with reports containing errors or fabricated findings. “This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” the company said.

The issue directly impacts the Google Open Source Software Vulnerability Rewards Program, which previously compensated researchers for identifying flaws in the company’s open source projects. With the program on hold, Google is encouraging participants to submit vulnerabilities through its other active bug bounty initiatives in the interim.

The move highlights the escalating challenge tech companies face in managing AI-driven spam within security research ecosystems, as automated tools make it increasingly difficult to distinguish genuine findings from noise.

Leave a Reply

Your email address will not be published. Required fields are marked *