Google has paused its Open Source Software Vulnerability Rewards Program due to a flood of low-quality AI-generated submissions that overwhelmed engineers with invalid reports and hallucinations. The program is suspended until at least Q1 2027, with participants redirected to other Google bug bounty programs in the interim.
Background
AI-generated content and automated tools have increasingly been used to submit reports to bug bounty programs, but many lack validity or contain hallucinated vulnerabilities, creating operational burdens for platforms.
- Source
- TechCrunch
- Published
- Oct 5, 2026 at 04:31 AM
- Score
- 6.0 / 10