Google 暂停开源漏洞赏金计划,称 AI 自动提交大幅增加
Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
Google 自 10 月 1 日起暂停其开源软件漏洞赏金计划(OSS VRP),原因是 AI 自动提交显著增加,绝大多数报告无效。公司承诺在 2027 年第一季度提供更新,期间建议参与者改用其其他漏洞赏金计划;据 Tom's Hardware,工程师和开源维护者被无效或含模型幻觉的报告淹没。
Blaming a “significant rise” in AI submissions, Google has paused its open source bug bounty program until next year.
Last year, TechCrunch reported that cybersecurity experts were warning of that AI slop posed a serious risk to bug bounty programs. Looks like that’s the issue confronting Google’s Open Source Software Vulnerability Rewards Program, where researchers were rewarded for finding vulnerabilities in the company’s open source software.
In posts on X and the program website, Google said the bug bounty program was paused as of October 1, with a promise to provide “an update” in the first quarter of 2027. According to Tom’s Hardware, Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations.
“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” the company said.
In the meantime, participants are encouraged to consider Google’s other bug bounty programs.
来源:TechCrunch:AI · techcrunch.com