$ techbeacon▋
CVE & Exploits

Google Halts Open‑Source Bug Bounty as AI‑Generated Reports Overwhelm Program

Google Halts Open‑Source Bug Bounty as AI‑Generated Reports Overwhelm Program

Google announced that it is temporarily suspending its Open Source Vulnerability Rewards Program after a sudden surge of submissions related to artificial‑intelligence‑driven security flaws. The pause, which the company says is intended to allow a review of the new submission flow, comes as developers and security researchers increasingly turn to AI tools for both finding and exploiting software weaknesses.

The Open Source Vulnerability Rewards Program, launched in 2016, has rewarded researchers who responsibly disclose bugs in widely used open‑source components such as Linux, Chromium and TensorFlow. In recent weeks, however, the program’s intake system has been inundated with reports that reference AI‑generated code, synthetic vulnerability descriptions, and automated scanning outputs. Google’s security team indicated that the volume and nature of these reports have made it difficult to triage and verify findings using existing processes.

According to a statement released by Google’s Vulnerability Reward and Bug Bounty (VR&BB) team, the surge is partly driven by the broader accessibility of large language models that can produce code snippets and suggest exploit strategies at scale. While these tools can accelerate legitimate research, they also enable the rapid creation of low‑quality or duplicate reports that strain the review pipeline. The company is therefore taking “a measured pause” to redesign its intake mechanisms, improve AI‑specific filtering, and ensure that high‑impact bugs continue to receive timely attention.

Industry observers note that the situation reflects a growing tension between the benefits of AI assistance in security work and the challenges of managing the resulting noise. Open‑source projects rely heavily on coordinated vulnerability disclosure to protect the millions of users who depend on them. If bounty programs become clogged with automated submissions, critical issues may be delayed, potentially exposing ecosystems to real‑world attacks. Google’s move signals that major platform operators are beginning to grapple with these operational realities.

Google has not provided a timeline for when the Open Source Vulnerability Rewards Program will resume, but it has pledged to keep the community informed of any procedural changes. In the interim, researchers are encouraged to follow existing guidelines for report quality and to use the company’s dedicated channels for high‑severity findings. The pause also serves as a reminder to the broader security community that as AI tools become more pervasive, both bounty programs and the organizations that run them will need to adapt their workflows to maintain effective, responsible vulnerability disclosure.

Threat Desk — Threat desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related