Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions

Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions

谷歌因 AI 提交内容“显著增加”而暂停其开源漏洞赏金计划

Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions. 谷歌因 AI 提交内容“显著增加”而暂停了其开源漏洞赏金计划。

Blaming a “significant rise” in AI submissions, Google has paused its open source bug bounty program until next year. 由于 AI 提交的内容“显著增加”,谷歌已暂停其开源漏洞赏金计划,直至明年。

Last year, TechCrunch reported that cybersecurity experts were warning that AI slop posed a serious risk to bug bounty programs. Looks like that’s the issue confronting Google’s Open Source Software Vulnerability Rewards Program, where researchers were rewarded for finding vulnerabilities in the company’s open source software. 去年,TechCrunch 曾报道称,网络安全专家警告说,AI 生成的垃圾内容对漏洞赏金计划构成了严重风险。看起来这正是谷歌开源软件漏洞奖励计划所面临的问题,该计划旨在奖励那些发现谷歌开源软件漏洞的研究人员。

In posts on X and the program website, Google said the bug bounty program was paused as of October 1, with a promise to provide “an update” in the first quarter of 2027. 在 X 平台和项目网站的公告中,谷歌表示该漏洞赏金计划已于 10 月 1 日起暂停,并承诺在 2027 年第一季度提供“最新进展”。

According to Tom’s Hardware, Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations. “This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” the company said. 据 Tom’s Hardware 报道,谷歌工程师和开源维护者被大量无效或包含“幻觉”的报告淹没。该公司表示:“此次暂停是由于自动化提交的内容显著增加,其中绝大多数都是无效的。”

In the meantime, participants are encouraged to consider Google’s other bug bounty programs. 在此期间,建议参与者考虑谷歌的其他漏洞赏金计划。