Google Halts Open Source Bug Bounty Until 2027 Due to AI Spam
Google has decided to halt its open-source bug bounty program indefinitely, extending the freeze until at least the first quarter of 2027. The decision comes after an influx of low-quality, AI-generated bug reports overwhelmed the company's engineering teams. These submissions, often inaccurate or fabricated, consumed significant time and resources, diverting attention from genuine security risks.
According to Google, the surge in automated AI-generated reports made it difficult for engineers and open-source maintainers to identify and address real vulnerabilities. Many of these submissions were found to be unexploitable or entirely fabricated, affecting core projects like Golang, Angular, Fuchsia, and critical GitHub actions.
While product vulnerability reports are paused, other aspects of the program remain active. Researchers can still submit high-impact fixes through the Google Patch Rewards Program, which offers up to $15,000 for verified code patches. Additionally, reports covering specific Google Cloud repositories remain open through the separate Cloud VRP.
Google is not alone in facing this challenge. Other tech companies, including Intel and the maintainers of the Linux kernel and curl utility, have also reported being overwhelmed by AI-generated spam submissions. Intel recently removed financial rewards from its bug bounty program, highlighting the growing struggle for security teams worldwide.