Google pauses bug bounties for open source because AI slop reports are drowning its reviewers
Google is temporarily pausing monetary rewards for capable bug hunters because its human staff can't keep up with the current influx of automated reports. The "vast majority" of these submissions are slop, Google warns, containing invalid information and hallucinated vulnerability data. Read Entire Article
Generative AI models are causing a flood of bogus vulnerability reports in open-source projects, forcing Google to pause its bug bounty program. The Google Bug Hunters team has halted the acceptance of new product vulnerability submissions, citing an overwhelming number of automated, low-quality reports that make proper vetting impossible.
These so-called "vibe-coded" reports contain invalid information and fabricated vulnerability data. The Open Source Software Vulnerability Rewards Program (OSS VRP) is responsible for paying researchers who find bugs in Google's open-source projects, including Go, Angular, and Fuchsia. Google is reforming the program and expects to announce changes in Q1 2027.
The company has made an exception for supply chain reports and dangerous vulnerabilities, but otherwise, it's redirecting capable bug hunters to other programs and its Patch Rewards Program. This issue is affecting other major open-source projects like Microsoft Edge and Linux, with smaller teams opting to close their doors to AI-generated contributions to avoid being swamped by the slop.
Written by urgent.news from TechSpot's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.