Google pauses bug bounties for open source because AI slop reports are drowning its reviewers

Alfonso Maruccia

Posts: 2,764   +1,080
Staff
Security slop: Generative AI models are exceptionally good at working with code, and vibe coding is now spilling over everywhere. So much so, in fact, that many open-source projects are struggling with an untenable volume of contributions if they want to keep a proper vetting process in place.

Google is temporarily pausing monetary rewards for capable bug hunters because its human staff can't keep up with the current influx of automated reports. The "vast majority" of these submissions are slop, Google warns, containing invalid information and hallucinated vulnerability data.

Tech Trivia: Which tech company launched the world's first bug bounty program?

The program being paused is Google's Open Source Software Vulnerability Rewards Program (OSS VRP), which the company designed to encourage capable researchers to report vulnerabilities in Google's own open-source projects. Researchers get paid for their findings, and Google benefits from better, more secure code in Go, Angular, Fuchsia, and other major FOSS codebases.

Then came vibe coding. The Google Bug Hunters team recently announced that the OSS VRP is no longer accepting product vulnerability submissions. The pause follows a significant rise in automated reports that put too much strain on reviewers. On top of that, the majority of these vibe-coded reports are simply useless.

Google also updated the OSS VRP rules to say the program won't accept new vulnerability reports submitted after October 1, while reports filed before then are still being processed. Some Google Cloud repositories might still accept new reports, but the main VRP is being "reformatted" to cope with the new chaos vibe coding has brought to the open-source world. Google plans to share an update on the program's future in the first quarter of 2027.

Google is making a specific exception for supply chain reports, which can have a massive reach compared to other "simpler" bugs. Reports about particularly dangerous flaws are safe as well. In any case, Mountain View is directing capable bug hunters looking for a reward to other VRPs that still accept reports, as well as its Patch Rewards Program.

Vibe coding is now seeping into every open-source codebase with public access. Microsoft Edge, Linux, and other major FOSS projects are facing the same issues as Google, while smaller teams have simply decided to shut the door on AI-generated contributions to avoid being overwhelmed by slop.

Permalink to story:

 
Wait, I thought just recently we were being told that AI was our savior and that we must win the AI arms race at all costs, people or environment be damned. Now you are telling me that Google thinks it just generates slop and makes things up and is becoming an issue for them. The irony of it all.
 
Wait, I thought just recently we were being told that AI was our savior and that we must win the AI arms race at all costs, people or environment be damned. Now you are telling me that Google thinks it just generates slop and makes things up and is becoming an issue for them. The irony of it all.

Google are pausing a bounty programme because humans have to review the flood and Google may have to pay successful submissions. These are user submitted bug reports. If people can mass generate plausible submissions for free and send them to a programme that pays out, obviously it gets flooded.

There is no irony. “AI makes spam cheaper” is not the same argument as “AI is useless”, however excited it makes you to say it.

And an AI arms race rather obviously means the technology is still developing, not that today's models are supposed to be the finished product.
Other than every word and everything you said, excellent analysis. Makes sense that you were so pleased with yourself.
 
AAAAAAAAAAAAAAAIIIIIIIIIIIIIIIIIIIIIII is so omnipotent that it can code flawlessly, poses an existential threat to humanity, is smarter than the average person and is universally above mankind, but it can't stop hallucinating.

The doom propaganda and final admission that it's useless is hilarious.
 
Google are pausing a bounty programme because humans have to review the flood and Google may have to pay successful submissions. These are user submitted bug reports. If people can mass generate plausible submissions for free and send them to a programme that pays out, obviously it gets flooded.

There is no irony. “AI makes spam cheaper” is not the same argument as “AI is useless”, however excited it makes you to say it.

And an AI arms race rather obviously means the technology is still developing, not that today's models are supposed to be the finished product.
Other than every word and everything you said, excellent analysis. Makes sense that you were so pleased with yourself.
I am not anti-AI at all. I use it daily and it has some really powerful use cases, when used correctly as a tool.

In my comment I am calling out the hypocrisy of the fact that the big tech companies saying that AI is everything and that they need all the money in the world to to keep pushing it, no matter the human or environmental cost.

Yet, Google has already found out that there are real limitation to how far AI can be used. It turns out that AI is not the panacea they claim it to be. In fact the article specifically states: The "vast majority" of these submissions are slop, Google warns, containing invalid information and hallucinated vulnerability data. You only focused on the first part of that paragraph where it states human staff can't keep up and then ignored the reason why the can't keep up.
 
Sounds like the only practical solution would be to make contributors on major projects be something you need to "audition" for. Using AI to identify bugs and their fixes isn't necessarily the problem; blindly clicking "submit" without reviewing these """bugs""" and their """fixes""" is. If someone uses an AI model to ID a bug and a fix, who cares, as long as they double checked the validity of the bug, the validity and effectiveness of the fix, and wrote documentation explaining both.

Let people audition for bug bounty programs, and be evaluated on what kind of 'bounty reports' they create, and then decide if they can contribute to a repo or not.
 
Back