Google Freezes Bug Bounty Program Amid AI Submission Surge
Google has temporarily suspended its Open Source Software Vulnerability Rewards Program due to an overwhelming influx of automated submissions from AI systems. The program, which rewards researchers for finding vulnerabilities in Google's open source software, was paused as of October 1 and is expected to resume next year.
The rise in automated submissions has led to a significant burden on Google engineers and open source maintainers, who are struggling to validate the reports. According to Tom's Hardware, most of these submissions contain invalid or hallucinated information, which requires additional time and resources to review.
In an effort to mitigate this issue, participants in the program are encouraged to consider other bug bounty programs offered by Google.