Fake Reports Flood Google as AI Disrupts Its Vulnerability Detection Program

Google has decided to suspend the submission of some vulnerability reports related to open-source software following a sharp increase in automated reports generated using artificial intelligence tools, the majority of which reportedly fail to meet the criteria required to qualify as genuine security vulnerabilities.

The company announced that it would temporarily stop accepting product vulnerability reports under the Google Open Source Software Vulnerability Rewards Program (OSS VRP). Google is expected to provide an update on the future of the program during the first quarter of 2027.

The program is designed to reward security researchers who successfully identify genuine vulnerabilities in Google’s open-source software. However, the massive influx of automated reports has placed additional pressure on the teams responsible for reviewing them.

According to a TechCrunch report, the decision came after Google engineers and open-source project maintainers faced a growing number of submissions containing errors and inaccurate information. In some cases, artificial intelligence reportedly identified vulnerabilities that did not actually exist or significantly overstated their severity.

Google explained that the suspension was prompted by a “significant increase in automated reports,” noting that the vast majority of them were invalid. This has substantially increased the workload of security teams, which must examine each report to determine whether the vulnerability can actually be exploited and assess its real-world impact before taking any action.

The move comes after Google had already begun revising the program’s rules earlier this year in response to the growing number of reports generated using artificial intelligence tools.

The company had previously said it had identified reports containing what it described as “hallucinations” regarding methods for exploiting vulnerabilities. Other submissions highlighted software bugs that were technically valid but did not pose an actual security threat.

The decision does not apply to all of Google’s vulnerability-reporting channels. The company continues to encourage researchers to use its other security reward programs, while certain types of reports are still being accepted and processed through separate programs.

Google’s decision highlights a growing challenge facing the cybersecurity industry as the use of artificial intelligence expands. While AI tools can accelerate the search for vulnerabilities, their automated use can also overwhelm security teams with large volumes of low-quality reports, making it more difficult to identify genuinely critical vulnerabilities amid the flood of submissions.

شاهد أيضا