• Tech Tech

Google paid bug hunters to find open-source flaws, then AI flooded the queue with made-up bugs

Legitimate vulnerabilities could face delays before they are reviewed and fixed.

A hand points at a computer screen with system warning alerts.

Photo Credit: iStock

A flood of AI-assisted bug filings pushed Google to halt a rewards program that pays for flaws found in its open-source software. Rather than keep human reviewers buried in reports the company considers unreliable or made up, it paused the effort.

Here's what to know

According to TechSpot, Google stopped taking product vulnerability submissions through its Open Source Software Vulnerability Rewards Program. Google tied the move to a surge in automated reports that reviewers could not keep up with.

Google launched the OSS VRP to pay security researchers who find vulnerabilities in its open-source projects, including Go, Angular, and Fuchsia. Useful submissions can reward researchers and help Google close security gaps.

Google's Bug Hunters team said it will no longer accept those submissions. Updated program rules also state that reports filed after Oct. 1 would be rejected, while submissions filed before Oct. 1 were under review.

More background

Open-source software underpins browsers, developer tools, cloud systems, and many consumer apps. If maintainers are forced to spend time debunking bad artificial intelligence reports, legitimate vulnerabilities could face delays before they are reviewed and fixed.

Google is not the only platform dealing with this problem. Microsoft Edge, Linux, and other open-source projects are running into similar issues. Some small teams have responded by refusing AI-generated contributions.

What's being done?

Google will still make room for supply chain reports, which can affect many downstream users at once along with disclosures involving especially dangerous flaws that pose unusually high security risks.

A handful of Google Cloud repositories may still accept new reports, leaving researchers with a narrow disclosure path while the broader OSS VRP is "reformatted."

For bug hunters seeking compensation, Google is directing them toward other vulnerability rewards programs and its Patch Rewards Program.

Google said an update on the main rewards program's status is planned for the first quarter of 2027.

Where can I learn more?

Google's bug bounty pause comes as the company faces pushback over how aggressively it is rolling out AI across its business.

• In the EU, antitrust scrutiny of Google's AI arrived as regulators questioned its market power.

• Across Gmail and Workspace, Google's AI email assistant has frustrated users who cannot switch it off.

• As Google leans into AI, users are drifting to DuckDuckGo after search results drew ridicule.

• Google CEO Sundar Pichai said no company is immune if the AI bubble bursts.

• At Google, one VP noted young employees will treat AI as part of everyday work.

Get TCD's free newsletters for easy tips, smart advice, and a chance to earn $5,000 toward home upgrades. To see more stories like this one, change your Google preferences here.

Cool Divider