ComputerWeekly

AI slop overwhelms Google’s OSS bug bounty programme


Google has temporarily suspended its open source software vulnerability reporting programme (OSS VRP) until at least the start of 2027, claiming it is being overwhelmed by a large volume of invalid AI slop bug reports.

Recent months have seen a surge in AI-assisted vulnerability reports – resulting in record-breaking patch updates from major tech suppliers such as Microsoft – but it is now becoming increasingly apparent that AI is not always the most helpful tool.

“We are temporarily no longer accepting OSS VRP product vulnerability submissions. This does not impact OSS VRP supply chain reports, or any outstanding reports,” Google said in a statement posted to social media platform X.

“As an alternative, we encourage you to find impact across our other VRP programmes and submit there instead, or pursue the Patch Rewards Program.

“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid. We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027,” said Google.

The four-year-old OSS VRP is designed to support vulnerability discovery across OSS stored in repositories run by Google-owned GitHub organisations, and a few selected repositories hosted on other platforms.

It also covers OSS repository configuration settings such as GitHub actions, access control rules and app configurations. Vulnerabilities in third-party dependencies have also been historically included in the scheme.

Payments made under the auspices of the OSS VRP range from $500 (£375) for security issues in OSS projects classed by Google as Important (OT1) to over $30,000 (£22,600) for supply chain compromises in Flagship (OT0) projects – a list of which can be found here.

AI finds more consequential flaws

According to a September 2026 study conducted by Google’s Threat Intelligence Group (GTIG), the overall number of vulnerabilities disclosed per month has doubled so far this year, rising from 5,045 in January to 10,740 in August.

The number of those that are being exploited in the wild has also risen rapidly, from an average of 10.5 per month in 2025 to 18 per month so far this year, although zero-day exploitation is growing at a slower rate.

Arguably of greater concern to defenders, GTIG found that AI-assisted vulnerability discovery was unearthing proportionally fewer low-risk flaws, more moderate-risk flaws, and more flaws that could lead to remote code execution (RCE) – often the ultimate goal for ransomware gangs.

GTIG also found that publicly-available data on AI-assisted vulnerability discoveries is likely a significant undercount of the true number due to two structural dynamics.

Firstly, public repositories of common vulnerabilities and exposures (CVEs) don’t yet feature uniform metadata tags for AI attribution, it said.

Secondly, cloud and software-as-a-service (SaaS) providers are often remediating AI-surfaced flaws directly in production without requesting formal CVE identifiers, which are more typically reserved for flaws that occur in on-prem kit, or third-party assets that require coordinated patching at end-user organisations.

“GTIG expects that vulnerability discovery and exploitation will continue to grow in the short to medium term,” the unit’s researchers said.

“To counter the increased risk from rapid vulnerability discovery and exploitation, organisations must transition from unprioritised mass-patching to threat-intelligence-driven triage, combining targeted edge-defence with automated, agentic remediation.”



Source link