Google freezes bug bounty program amid AI spam surge
Google has put a temporary hold on its open source bug bounty program due to a surge in low-quality, AI-generated submissions. The company describes this as a 'significant rise' in automated reports, which are overwhelming the program's review process. This move highlights a broader issue in the tech industry, where AI tools are flooding security programs with spam, making it difficult to distinguish legitimate vulnerabilities from automated noise.
The freeze impacts Google's extensive open source ecosystem, including key projects like Android, Chrome, and TensorFlow. Security researchers who rely on these programs for income now face uncertainty about when normal operations will resume. Industry sources indicate that the quality degradation has become so severe that manual review processes can no longer keep up.
This challenge is not unique to Google. Microsoft, Apple, and other major tech companies are also grappling with similar issues as AI tools become more adept at generating security reports. The irony is that AI, designed to aid in identifying bugs, is now making it harder for companies to pinpoint real vulnerabilities. Some firms are experimenting with AI-powered filtering systems to separate legitimate submissions from automated spam.
Google has not provided a timeline for when the program might resume, but sources suggest the company is working on enhanced filtering mechanisms. The solution likely involves a combination of technical screening tools and updated submission guidelines that require more detailed human analysis. The economic implications are significant, as bug bounty programs serve as a crucial income source for many independent security researchers, particularly in developing countries.