AI-generated “flood of vulnerability reports” overwhelms review team Google suspends some open source bug bounty programs

📅 2026-10-04

Abstract:

Google announced that it has suspended the product vulnerability submission channel in its Open Source Software Vulnerability Reward Program (OSS VRP). The reason is that a large number of invalid vulnerability reports generated by artificial intelligence continue to pour in, putting huge pressure on engineers and open source maintainers responsible for review. According to a notice issued by Google on October 1, this suspension has officially taken effect, and the company expects to provide further updates in the first quarter of 2027 after readjusting the relevant mechanisms.

OSS VRP is a security reward program established by Google for the open source ecosystem, aiming to encourage independent researchers to discover and responsibly disclose security vulnerabilities. In this project, the product vulnerability category mainly covers code defects, logic errors, design vulnerabilities and other issues in Google's public code repository.

Google stated that this suspension only targets product vulnerability submission categories and does not affect reports that have been submitted before October 1. At the same time, supply chain security reports in OSS VRP will continue to accept submissions. For some code warehouse vulnerabilities affecting Google cloud products, the company may still continue to receive relevant reports through the Cloud VRP channel.

It is understood that traditional vulnerability research often requires researchers to invest a lot of time analyzing code, verifying problems and writing complete technical reports. However, with the rapid popularity of large language models and automated vulnerability mining tools, the threshold for generating vulnerability reports has been greatly lowered. More and more users are beginning to use AI to automatically scan codes and generate vulnerability submissions in batches.

The problem is that a lot of these reports have no real value. Many reports claim to have discovered security flaws, but after manual review, it is found that they are either model "illusions" or there are no exploitable vulnerabilities at all. Since all reports still need to be checked one by one by the security team, a lot of time is spent verifying misinformation instead of dealing with the real critical security issues.

Industry insiders pointed out that this kind of phenomenon has gradually spread in the open source community and the security industry. With generative AI tools able to quickly produce professional-looking technical analysis, bug bounty programs are facing unprecedented screening pressure. Vulnerability research work that originally relied on manual expertise is now diluted by a large number of low-quality automated submissions.

Google engineers and open source project maintainers are said to have been plagued by thousands of invalid reports. Some reports are well-structured and described in detail, but after verification, it is found that no real vulnerability exists. Maintenance teams have to put a lot of effort into troubleshooting these error messages, which delays real security issues.

In fact, this is not the first time a similar situation has occurred. The Linux community has also come under pressure before due to a large number of false vulnerability reports generated by AI. Some maintainers have publicly stated that they have to spend more and more time dealing with non-existent problems instead of fixing real defects. Some projects have even adjusted related workflows as a result.

People in the security research field believe that this incident reflects the new challenges brought by generative AI. While artificial intelligence can indeed help researchers identify potential problems, large-scale automated reporting can also burden the security ecosystem without adequate verification mechanisms.

Google said that researchers can continue to participate in other bug bounty programs while the related review and submission processes are redesigned. The company hopes to balance the relationship between AI-assisted research and reporting quality through new mechanisms to resume normal operations of related programs in the future.

Related tags

Related articles

Comments

0/500
Captcha (click to refresh)
No comments yet