Skip to content
TechCrunch·

🔒Google Pauses Open Source Bug Bounty Program Due to AI Submissions

AI submissions overwhelm Google's bug bounty program

TL;DR

Google has paused its open source bug bounty program due to a surge in AI-generated submissions, overwhelming engineers and maintainers. The program will resume in 2027 with updates.

Google has paused its Open Source Software Vulnerability Rewards Program due to an overwhelming number of AI-generated submissions, most of which were invalid or contained hallucinations. This pause highlights the challenges AI poses to traditional bug bounty programs, affecting the workflow of security researchers and open source maintainers. The program was paused as of October 1, 2023, and will resume in the first quarter of 2027 with updates to address the issue of invalid submissions. Participants are encouraged to consider Google's other bug bounty programs.

Google Pauses Open Source Bug Bounty Program Due to AI Submissions — TechCrunch

Key Points

1

Google's Open Source Software Vulnerability Rewards Program paused as of October 1, 2023.

2

The majority of AI submissions were invalid or contained hallucinations.

3

Google engineers and open source maintainers were overwhelmed by the influx of reports.

4

Participants are encouraged to consider Google's other bug bounty programs.

5

The program will resume in the first quarter of 2027 with updates.

Why It Matters

Security researchers and open source maintainers are facing challenges due to the influx of AI-generated submissions. The pause affects the workflow and efficiency of these programs, potentially delaying the discovery and resolution of actual vulnerabilities. Researchers and maintainers should adapt their strategies to navigate the new landscape of AI-generated submissions.

googleopen-sourceaibug-bountycybersecurity

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,549 builders reading daily.

Also get