Google praised AI for finding bugs. Now it has too many reports, not enough bugs
AI made bug hunting easier. Now Google is dealing with the fallout.
Google has stopped accepting product vulnerability reports through its OSS VRP (Open Source Software Vulnerability Reward Program) due to a surge in automated submissions filled with invalid data, primarily AI-generated reports. The company had previously warned in March about the rapid increase in AI-generated bug reports, including hallucinated bugs and low-impact issues.
This development comes at a time when Google has been actively promoting the benefits of AI in software security, noting that AI agents are finding bugs that humans often miss, uncovering vulnerabilities hidden deep within code for years, and scanning massive codebases at a pace far exceeding that of human security teams. Executives at Google have even dubbed some of these AI tools as game-changers in the field.
However, this success story has a twist. The very AI that has proven so effective in bug hunting has led to Google having to close one of the main channels for reporting vulnerabilities. The search giant has temporarily halted the acceptance of product vulnerability submissions through its OSS VRP, citing the overwhelming volume of automated submissions as the reason behind this decision.
Written by urgent.news from Android Authority's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.