search
Google Bug Bounty Program
Trends
- 1Google pauses open-source bug bounty as AI reports flood in▼Google freezes open-source bug bounty program amid flood of invalid AI slop submissions — product flaw submissions halted until 2027 as maintainers drown in hallucinations
Google has halted open-source bug bounty submissions until 2027 after a wave of low-quality, AI-generated reports overwhelmed engineers and open-source maintainers. The company says many submissions are invalid or hallucinated, and reviewing them has become unsustainable. The freeze reflects a wider problem: automated tools are flooding vulnerability programs with noise, drowning out legitimate security research.
- 2Google pauses open-source bug bounty amid flood of AI-generated spam●Google freezes open-source bug bounty program amid flood of invalid AI slop
Google has suspended part of its open-source vulnerability reward program, halting submissions for product vulnerabilities as of October 1, after being flooded with invalid reports generated by AI tools. The company says low-quality automated 'slop' submissions overwhelmed reviewers, making genuine security reports harder to process. Security researchers are debating whether other bug bounty programs could face the same problem.
- 3Google pauses open source bug bounty amid flood of AI reports▼Google pauses open source bug bounty program after rise in AI submissions
Google has temporarily paused its open source bug bounty program, which paid researchers for finding vulnerabilities in open source projects, after a surge in submissions generated by artificial intelligence tools. The company says many AI-written reports are low quality and waste reviewers' time. Security researchers are debating how bounty programs should handle automated submissions and verify genuine human findings.
- 4Google Narrows Open Source Bug Bounty Program▼Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports
Google is restricting eligibility in its open source bug bounty program, citing a flood of invalid automated reports flooding its security team. The change means many AI-generated or low-quality vulnerability submissions will no longer qualify for rewards. Security researchers are debating whether the move will protect triage resources or discourage legitimate findings at a time when automated tools are producing huge volumes of dubious reports.
- 5Google Suspends Open-Source Bug Bounty Over AI Vulnerability Flood▼Google Suspends Open-Source Bug Bounty Due to AI Vulnerability Reports
Google has suspended its open-source bug bounty program, citing the volume of vulnerability reports generated by artificial intelligence tools. The company said AI-assisted submissions have flooded the program with low-quality or invalid reports, making it difficult for reviewers to identify genuine security flaws. The move has drawn attention from security researchers, who are debating how bug bounty programs should adapt to AI-generated submissions.
- 6Google pauses bug bounty program over flood of AI-written reports▼Google pauses its open-source bug bounty program after a flood of AI slop reports
Google has paused its open-source bug bounty program after being overwhelmed by a wave of low-quality, AI-generated vulnerability reports. The company says the influx of automated, low-effort submissions is drowning out genuine findings and wasting researchers' time, prompting a suspension while it reassesses how the program operates.
- 7
Google has paused its open source bug bounty program after being overwhelmed by a wave of AI-generated vulnerability reports. The automated submissions have flooded reviewers with low-quality, often invalid findings, making the program difficult to manage. The move highlights a growing problem for security teams as generative AI tools make it easy to mass-produce bug reports that look plausible but waste researchers' time.
- 8Google pauses open source bug bounty program over flood of AI submissions▼Google benches open source bug bounty program following ‘significant rise’ in AI submissions
Google has shelved its open source bug bounty program, citing a significant rise in AI-generated vulnerability reports that analysts say offer little real value. Security researchers have long complained that automated tools mass-submit low-quality or duplicate findings, overwhelming triage teams. The move has reignited debate in the security community over how AI is reshaping responsible disclosure, and whether legitimate reports are being drowned out by machine-generated noise.
- 9
Google has temporarily paused its open source bug bounty program, citing a surge in low-quality AI-generated vulnerability reports. The program paid researchers for finding security flaws in Google's open source projects. The pause suggests AI tools are flooding security teams with automated submissions that are difficult to review, raising concerns across the security research community about how bounty programs will handle AI-driven noise.
- 10AI slop floods Google's open-source bug bounty▼AI slop submissions force Google to freeze its open-source bug bounty
Google has paused its open-source bug bounty program after being overwhelmed by low-quality, AI-generated vulnerability reports. The flood of automated 'slop' submissions is drowning out genuine security findings and forcing reviewers to waste time on junk, prompting the freeze. The case highlights how generative AI tools are now being misused to mass-produce fake or trivial bug reports for bounty rewards.
- 11
Google has paused its open-source bug bounty program, which paid researchers for reporting vulnerabilities in projects like Bazel, Angular, Golang, and Protocol Buffers. The company said it was overwhelmed by a flood of low-quality, AI-generated submissions from bounty hunters, making the program difficult to sustain. The move has sparked debate among security researchers about the impact of automated AI spam on vulnerability disclosure programs.
- 12Google pauses open source bug bounty program citing flood of AI reports●Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
Google has frozen its open source bug bounty program, citing a significant rise in submissions generated with the help of AI. The company says automated, low-quality vulnerability reports are overwhelming reviewers, making it harder to identify genuine security flaws. The move highlights a growing problem across the security industry as AI tools make it easy to mass-produce plausible-looking bug reports.
- 13Google pauses open-source bug bounty program amid submission surge●Google Just Hit Pause on Its Open-Source Bug Bounty Program —Explosive Surge in Submissions Has Left the
Google has temporarily paused its open-source bug bounty program, which paid researchers for reporting vulnerabilities in open-source projects. The company cited an explosive surge in submissions as the reason, and reports suggest the volume of reports has left the program unable to keep up while Google reviews how to handle the influx.