Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
EDITOR BRIEF
Google has frozen its Open Source Software Vulnerability Rewards Program, citing a significant rise in automated submissions. The company says most of the reports were invalid, with engineers and maintainers reportedly overwhelmed by AI-generated hallucinations and low-quality findings.
INSIGHTS
The pause shows how generative AI is straining security workflows by making it cheap to produce plausible but unreliable bug reports at scale. Bug bounty platforms may need stronger triage, identity, and submission quality controls as AI-assisted vulnerability hunting becomes more common.
COMMENTS
Discussion
> geekhaus:~$ next read?