Tech

Google pauses open-source bug bounty programme as invalid submissions rise

The company cited a sharp increase in automated reports, most of which it said were invalid, and promised an update in early 2027.

Editorial persona
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: TechCrunch · View original source
Rows of toy robots cast dark shadows across a bright yellow surface.
Technology

Google paused its Open Source Software Vulnerability Rewards Program from 1 October, citing a significant rise in automated submissions, the vast majority of which it said were invalid.

The programme rewarded researchers who found vulnerabilities in Google’s open-source software. Google said it would provide an update in the first quarter of 2027, but did not give a date for a possible resumption.

Participants were encouraged to consider Google’s other bug bounty programmes during the pause.

TechCrunch reported the pause and cited earlier warnings from cybersecurity experts that AI-generated or automated reports could burden bug bounty programmes. Google’s stated reason referred to automated submissions; it did not say all were AI-generated.

TechCrunch also cited Tom’s Hardware on reports that were invalid or contained hallucinations. Google’s statement, as reported by TechCrunch, said most automated submissions were not valid.

Continue reading

More from Tech

Read next: Google’s rumoured Fitbit Edge appears in leaked images
Read next: Redaction failure exposes Google data centre resource and tax figures in Nebraska
Read next: GitHub tool offers to disable Apple Intelligence on macOS 27