Tech & AI
Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
Blaming a “significant rise” in AI submissions, Google has paused its open source bug bounty program until next year.
Last year, TechCrunch reported that cybersecurity experts were warning of that AI slop posed a serious risk to bug bounty programs. Looks like that’s the issue confronting Google’s Open Source Software Vulnerability Rewards Program, where researchers were rewarded for finding vulnerabilities in the company’s open source software.
In posts on X and the program website, Google said the bug bounty program was paused as of October 1, with a promise to provide “an update” in the first quarter of 2027. According to Tom’s Hardware, Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations.
“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” the company said.
In the meantime, participants are encouraged to consider Google’s other bug bounty programs.
Google OSS VRP: History and Scope
Google’s Open Source Vulnerability Rewards Program (OSS VRP) was launched in August 2022. It rewards security researchers for identifying vulnerabilities in Google’s open-source software projects.
The program covers the latest versions of open-source software hosted in public repositories owned by Google on GitHub, as well as selected repositories on other platforms.
It also includes repository configuration settings, such as GitHub Actions workflows, access control rules and GitHub application configurations.
Rewards range from $100 to $31,337 based on the severity level of the reported flaws and the project’s importance.
The OSS VRP is one of several bug bounty programs operated by Google and has a relatively narrow focus.
Vulnerabilities in Google’s open source projects that are closely linked to Google Cloud or AI products are directed to the Google Cloud Vulnerability Reward Program (Cloud VRP) or the AI Vulnerability Reward Program (AI VRP), allowing reports to be routed to the teams best placed to assess and address them.
Google Plans OSS VRP Overhaul
The suspension will not affect OSS VRP supply-chain reports or any reports already submitted, Google said.
The company plans to “reformat” the program and expects to provide an update in the first quarter of 2027.
“As an alternative, we encourage you to find impact across our other VRP programs and submit there instead, or pursue the Patch Rewards Program,” Google said.
You must be logged in to post a comment Login