Google Suspends Open-Source Bug Bounty Program Amid Surge in AI Hallucinations

0
1

Key Takeaways

  • Google has paused product‑vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP) because of a surge in low‑quality, AI‑generated bug reports.
  • The suspension took effect on 1 October 2024 and does not affect reports filed before that date, Cloud VRP submissions, or supply‑chain reports.
  • Google expects to share an update on the program’s redesign by Q1 2027 and encourages researchers to use other VRP offerings in the meantime.
  • Similar pressures have forced Linux kernel maintainers and Intel’s bug‑bounty team to curb or suspend their programs amid overwhelming numbers of AI‑hallucinated findings.
  • The move highlights a growing industry challenge: balancing the accessibility of large language models (LLMs) for security research with the need to keep bounty programs manageable and effective.

Overview of the Suspension

On 1 October 2024, Google announced via an official X (formerly Twitter) post that it was suspending product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP). The tech giant wrote:

“Google has officially suspended product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP) — a bug bounty program — over an influx of invalid AI‑driven reports.”

The pause began the same day the statement was released and will remain in place while Google “re‑formats and works on this aspect of the program.” The company promised to issue an update by the first quarter of 2027, giving researchers a clear, albeit distant, horizon for when the program might resume accepting new product‑flaw submissions.


What Is the OSS VRP?

The OSS VRP is a specialized bounty initiative that rewards independent security researchers for uncovering responsibly disclosed flaws in Google’s open‑source codebase. Under the program, product vulnerability submissions focus on code defects, logic errors, or design bugs residing in Google’s publicly available repositories. Historically, uncovering such issues required painstaking manual analysis, deep familiarity with the code, and a high degree of expertise—qualities that justified the often‑substantial payouts attached to valid findings.

By contrast, the program also accepts supply‑chain reports and vulnerabilities reported through the Cloud VRP for certain Google Cloud repositories; those streams remain untouched by the current suspension.


Impact of AI‑Generated Reports

The core reason for the halt is an explosion of low‑effort, AI‑driven bug reports that have inundated Google’s security triage teams. Large language models (LLMs) and automated AI bug‑hunting scripts have dramatically lowered the barrier to producing a vulnerability report. Researchers can now prompt an LLM to scan a repository and output a list of putative flaws in minutes, a task that once demanded hours or days of manual code review.

Google engineers and open‑source maintainers described being “overwhelmed by thousands of these poorly written reports that claimed to find bugs but were actually completely invalid or unexploitable hallucinations.” As a result, valuable engineer time is diverted from actually fixing critical vulnerabilities to the tedious chore of validating spurious claims. The net effect is a reduction in the program’s overall security return on investment.

A telling quote from the original announcement captures the dilemma:

“They ended up spending too much time manually validating code instead of actually fixing real, critical vulnerabilities.”


Industry Parallels

Google’s decision is not isolated. Earlier in October 2024, Linux kernel maintainers reported being “completely overwhelmed” by CVE submissions after AI‑powered bug hunters pushed the kernel to a record 2,000 vulnerabilities per release. The sheer volume of noise made it difficult to separate genuine issues from AI‑generated false positives, prompting the Linux community to discuss tighter submission guidelines and more rigorous validation pipelines.

Similarly, Intel suspended its own bug‑bounty program, which previously offered rewards of up to $100,000 per flaw. While Intel has not explicitly blamed AI‑generated reports, industry analysts widely suspect that a deluge of low‑quality submissions played a role in the suspension.

These concurrent events underscore a systemic strain across the open‑source and proprietary software security ecosystems: the democratization of vulnerability discovery via AI is outpacing the capacity of human reviewers to triage the findings.


Google’s Response and Timeline

In its announcement, Google emphasized that the suspension applies only to new product‑vulnerability submissions filed on or after 1 October 2024. Reports submitted before that date will continue to be processed under the existing OSS VRP rules. The company also clarified that:

  • Cloud VRP remains available for certain Google Cloud repositories impacting Google Cloud products.
  • OSS VRP supply‑chain reports are unaffected, meaning researchers can still earn rewards for identifying risks in third‑party dependencies used by Google’s open‑source projects.

Google committed to providing an update by Q1 2027, a timeline that suggests a substantial overhaul rather than a quick tweak. During this interval, the company encourages participants to “explore other VRP programs,” likely referring to Google’s broader suite of bug‑bounty offerings (e.g., Chrome VRP, Android VRP, or specialized initiatives like the Play Protect Rewards Program).


Implications for Security Researchers

For independent researchers, the suspension reshapes the incentive landscape. Those who have honed skills in manually auditing Google’s open‑source code may now need to pivot toward:

  1. Alternative Google VRPs where product‑vulnerability submissions remain open (e.g., Chrome, Android).
  2. Third‑party bug‑bounty platforms (HackerOne, Bugcrowd, Synack) that continue to accept AI‑assisted submissions but often employ stricter validation or machine‑learning filters to curb spam.
  3. Supply‑chain and cloud‑focused research, which remain viable avenues under the unchanged OSS VRP and Cloud VRP streams.

The move also signals that researchers should exercise caution when relying solely on LLMs for vulnerability discovery. While AI can accelerate scanning and suggest potential issues, the current wave of hallucinations demonstrates that human oversight remains indispensable for confirming exploitability, assessing impact, and crafting high‑quality reports.


Looking Ahead: Rethinking Bounty Programs in the AI Era

Google’s planned redesign of the OSS VRP will likely incorporate several mitigation strategies already being tested elsewhere:

  • Automated pre‑filters that use LLMs or static analysis to score the plausibility of a submission before it reaches a human reviewer.
  • Higher evidence thresholds, requiring proof‑of‑concept exploits, detailed reproduction steps, or minimal viable patches alongside each report.
  • Rate‑limiting or reputation‑based gating, where trusted researchers earn higher submission quotas while newcomers face stricter scrutiny.
  • Community‑driven validation, allowing senior contributors to flag or downvote dubious reports, thereby reducing the load on Google’s internal security team.

Such measures aim to preserve the spirit of open collaboration that bounty programs embody while defending against the signal‑to‑noise degradation introduced by generative AI.

If successful, Google’s revamped OSS VRP could become a model for other tech giants grappling with similar challenges, illustrating how the industry can harness AI’s productivity gains without sacrificing the rigor essential to effective vulnerability management.


In summary, Google’s temporary halt on OSS VRP product‑vulnerability submissions is a direct response to an influx of AI‑generated, low‑quality bug reports that have overwhelmed its security engineers. The suspension, effective 1 October 2024, leaves pre‑existing reports, Cloud VRP submissions, and supply‑chain claims untouched, with a promised program update slated for Q1 2027. The episode mirrors broader trends across Linux, Intel, and other bug‑bounty efforts, highlighting the urgent need for smarter, AI‑aware triage mechanisms as the security community adapts to the new reality of LLM‑powered vulnerability discovery.

https://www.tomshardware.com/tech-industry/artificial-intelligence/google-suspends-part-of-the-oss-vrp-bug-bounty-program-due-to-an-influx-of-invalid-ai-submissions-product-vulnerability-submissions-ended-october-1

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here