Google benches open source bug bounty program following ‘significant rise’ in AI submissions

Advertisement


  • Google paused OSS bug bounty submissions after a surge of AI-generated, invalid reports
  • AI boosts vulnerability discovery but often produces flawed, incomplete, or hallucinatory findings
  • Rising AI-driven bounty spam has also overwhelmed curl maintainers and Linux security reviewers

Google has revealed it is pausing one of its bug bounty program and it’s all AI’s fault.

The company said its Open Source Software Vulnerability Rewards Program (OSS VRP) is being flooded with bogus and irrelevant submissions to the point where it was simply unmanageable.

Leave a Comment