Google suspends open source bug bounty program over invalid AI submissions
Google has suspended its Open Source Software Vulnerability Reward Program after a surge in invalid or hallucinated bug reports generated by AI. The company says the program is paused as of October 1 and promised an update by early 2027. Until then, researchers are encouraged to use other Google bug bounty programs. Google engineers and maintainers reportedly struggled to keep up with the volume of unhelpful reports.
Why it mattersThis move highlights new challenges posed by generative AI in cybersecurity, where low-quality or misleading submissions can overwhelm legitimate vulnerability hunting efforts. It may also influence how other organizations handle automated bug reports.
- Program paused due to rise in AI-generated false reports
- Suspension started October 1, update expected in early 2027
- Engineers struggled with overwhelming invalid submissions
- Researchers redirected to other Google bug bounty programs
Sources covering this
In this story
More in Cybersecurity
Citrix patches NetScaler zero-day flaw exploited in attacks
Citrix has issued emergency fixes for a NetScaler vulnerability (CVE-2026-88779) actively exploited in zero-day attacks targeting…