Google Pauses Open Source Bug Bounty Due to AI Hallucinations

0
23

Google is making a significant adjustment to its Open Source Software Vulnerability Reward Program (OSS VRP), announcing that it will stop accepting product vulnerability reports through this channel starting October 1, 2026. This change, however, will not affect vulnerability reports submitted before this date.

The tech giant clarified that while the OSS VRP will be phased out for general product vulnerabilities, specific exceptions will exist. For certain Google Cloud code repositories that could impact Google Cloud products, vulnerability reports may still be accepted via the Cloud VRP if they pertain to product vulnerabilities.

The OSS VRP was established as a dedicated security bounty program designed to encourage independent security researchers to discover and responsibly disclose security flaws within Google’s extensive open-source ecosystem. The program aimed to bolster the security of the open-source software that underpins much of the digital world.

AI Hallucinations Overwhelm Maintainers

According to reports, the decision to scale back the OSS VRP stems from an overwhelming influx of submissions, many of which are reportedly generated by artificial intelligence. Insiders familiar with the matter revealed to Tom’s Hardware that Google engineers and open-source code maintainers have been inundated with thousands of low-quality reports. These reports often falsely claim the discovery of serious vulnerabilities, but upon closer inspection, they turn out to be AI-generated “hallucinations” – essentially fake findings that are not exploitable in the real world.

This deluge of unsubstantiated reports has placed an immense burden on maintenance teams. They have been forced to dedicate substantial resources to verifying these inaccurate claims, diverting critical time and effort away from addressing and fixing genuine, high-risk vulnerabilities that pose a real threat to software security. This strain on resources is cited as the direct catalyst for Google’s decision to pause the program.

Future of OSS VRP

Google has stated its commitment to reorganizing and optimizing the mechanisms behind the OSS VRP. The company plans to provide an update on its progress and any new developments in the first quarter of 2027. This suggests that while the current iteration is being paused due to specific issues, Google may be exploring ways to relaunch or refine its open-source security incentive programs in the future, potentially with better mechanisms to filter out AI-generated noise.

The situation highlights a growing challenge in the cybersecurity landscape as AI capabilities advance. While AI can be a powerful tool for security research, its misuse or unverified outputs can create significant operational overhead, as demonstrated by this situation with Google’s OSS VRP. The company’s move underscores the need for robust validation processes and careful consideration of how AI impacts security reporting and reward programs.

Source: https://www.ithome.com/1/009/673.htm

LEAVE A REPLY

Please enter your comment!
Please enter your name here