Google pauses open source bug bounty after AI spam flood
Google has hit pause on its open-source software bug bounty program because AI-generated spam reports were getting out of hand.
They're taking some time to restructure the submission framework, with an official progress update slated for Q1 2027.
If you submitted a valid product vulnerability before October 1, those reports are still being handled.
Google still accepts supply chain reports
You can still report supply chain issues under the same program, and Google is encouraging security researchers to check out its other reward programs in the meantime.
Certain product vulnerability reports tied to Google Cloud repositories that directly impact Cloud products may still be accepted through the separate Google Cloud VRP.
This move follows Intel's recent freeze of its bug bounty program, while Linux maintainers reported being flooded by bogus CVE filings.