
According to a report from TechCrunch, Google has temporarily suspended its open-source bug bounty program. The decision follows a significant increase in the volume of submissions, which the company suggests has been driven by an influx of low-quality, AI-generated reports. This surge has reportedly overwhelmed the security teams responsible for triaging and verifying potential vulnerabilities.
Bug bounty programs are designed to incentivize independent security researchers to identify and report software flaws, allowing companies to patch them before they can be exploited by malicious actors. However, the rise of generative AI tools has made it easier for individuals to automate the creation of bug reports, leading to a flood of 'slop' or low-effort submissions that do not meet the technical standards required for legitimate security research.
Google has not yet provided a specific timeline for when the program might resume. The move highlights a growing tension between the democratization of security research through AI and the operational capacity of major tech firms to manage the resulting data. Industry analysts suggest that other major technology companies may face similar pressures as automated reporting becomes more accessible to the public.
For now, security researchers and contributors are advised to monitor official Google security channels for updates regarding the program's status. The company is expected to implement new filtering mechanisms or submission guidelines to better manage the quality of reports once the program is reinstated.
The report originates from TechCrunch, a credible outlet for technology news, citing a specific operational change at Google. While the story is currently single-sourced, it is consistent with industry-wide challenges regarding automated submissions in bug bounty programs.
No corroborating trusted sources found.
Original report: TechCrunch