Tuesday, October 6, 2026
Tech Beat
Oct 4, 2026, 8:31 PMCybersecurity

Google Pauses Open Source Bug Bounty Over Invalid AI Reports

Google paused its open source bug bounty after AI-driven reports surged, with most submissions invalid. An update is due in the first quarter of 2027.

Listen to this briefingAudio briefing

Summary

As of October 4, 2026, Google’s Open Source Software Vulnerability Rewards Program has been paused since October 1 following a significant increase in automated AI submissions. Google said the vast majority were invalid, while hallucinated reports overwhelmed its engineers and open source maintainers. The program rewards researchers for finding vulnerabilities in Google’s open source software.

Google will provide an update in the first quarter of 2027 but has not announced a firm reopening date. Until then, researchers cannot submit through this program and are encouraged to use Google’s other bug bounty programs.

Positives

  • A first-quarter 2027 update gives researchers a defined checkpoint for news about the paused program.
  • Google’s other bug bounty programs remain available to participants during the Open Source program’s suspension.
  • The Open Source Software Vulnerability Rewards Program has rewarded researchers for finding flaws in Google’s open source software.

Risks & concerns

  • The October 1 freeze removes a reward channel for researchers finding vulnerabilities in Google’s open source software.
  • Google said the vast majority of the increased automated submissions were invalid.
  • Invalid and hallucinated reports overwhelmed Google engineers and open source maintainers.
  • Google has promised a first-quarter 2027 update but has not set a firm reopening date.
Primary sourceTechCrunchhttps://techcrunch.com/2026/10/04/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions/
Read full article
Editorial note: Tech Beat summarizes and analyzes third-party reporting. The source link is the authoritative article. This page does not reproduce the full source text.

More From The Wire

CybersecurityOct 5

MCP Trust Flaws Let AI Agents Turn Prompts Into Internal Attacks

CybersecurityOct 5

Denmark CPR Breach Exposes Records of 8 Million People

CybersecurityOct 2

Apple Tightens macOS Full Disk Access as Meta Muse Raises AI Privacy Risks