Google has reportedly frozen product flaw submissions to its open-source bounty until 2027, as invalid AI-written reports pile up on maintainers.
Google has frozen submissions of product flaws to its open-source bug bounty program until 2027, according to a Tom's Hardware report. The reason, as the headline puts it: a flood of invalid, AI-generated submissions that maintainers have to read, test and reject.
We only have the headline and its framing to go on, so we will not pretend to know the details of the pause, the volume of reports or how Google measured the problem. What the framing does tell us is the direction of travel. A program built to reward careful human research has been overwhelmed by cheap, automated text that looks like research.

That asymmetry is the heart of it. A language model can produce a confident write-up of a vulnerability that does not exist, complete with plausible function names and a made-up proof of concept. Checking it means reading the code, trying to reproduce the issue and writing a polite rejection. Multiply that by hundreds and a bounty stops being a channel for security signal and becomes a denial-of-service attack on the people running it.
The hallucination problem is well documented elsewhere, from air traffic tooling to legislative debates. Bug bounties are just one more place where fabricated detail gets submitted as fact. The difference is that here the cost lands on volunteers and small teams, who often cannot afford a dedicated triage desk.
There is also a perverse incentive at work. Payouts reward volume for anyone who can automate the first draft, so the people most willing to spam are the ones with the least to lose. Honest researchers, who file fewer and better reports, get caught in the freeze along with everyone else. Pausing until 2027 protects the reviewers but punishes the people the program was meant to attract.
Our take: this is a blunt tool, and a telling one. A long freeze suggests filtering and reputation systems were not enough, or at least not fast enough. The useful follow-up question is what replaces open submission, whether that is verified reporters, mandatory reproducible proofs, or something else. Until then, security reporting for open-source software just got a little narrower, and that is a real cost, not a footnote.
Original source: Tom's Hardware
Produced with AI support and reviewed by the newsroom



Comentarios
Publicar un comentario