• Home
  • Google suspends open-source bug bounty…

Google suspends open-source bug bounty programme

Google has temporarily suspended its open-source bug bounty programme, citing a “significant rise” in submissions that has placed additional pressure on security researchers and maintainers.

The technology company said its Open Source Software Vulnerability Rewards Program was paused on October 1 and would remain suspended until next year.

Google announced the move in posts on X and on the programme’s website, saying it would provide an update in the first quarter of 2027.

The programme rewards security researchers who identify and report vulnerabilities in Google’s open-source software, helping the company and maintainers address potential security weaknesses.

However, the surge in submissions appears to have created challenges for the programme.

According to Tom’s Hardware, Google engineers and open-source maintainers have been overwhelmed by reports that were invalid or contained AI-generated “hallucinations”.

The development highlights growing concerns over the impact of generative artificial intelligence on bug bounty programmes, where researchers rely on accurate vulnerability reports to identify and fix security flaws.

Cybersecurity experts had warned last year that the increasing use of AI to generate vulnerability reports could result in large volumes of low-quality or inaccurate submissions, making it more difficult for security teams to identify genuine threats.

“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” the company said.

Google’s decision to pause the programme underscores the challenge facing organisations as AI tools become increasingly accessible to cybersecurity researchers and other users.