← Back to stories
AI

Google praised AI for finding bugs. Now it has too many reports, not enough bugs

Google has stopped accepting product vulnerability reports through its OSS VRP after a sharp rise in automated submissions, many of which it says are invalid.

The company had already warned in March about a massive surge in AI-generated reports, including hallucinated bugs and low-impact issues.

The timing is hard to ignore: Google has spent much of 2026 praising AI for making bug hunting faster, easier, and far more productive.

Google has been doing a pretty good job of showing off what AI can do for software security. Its AI agents are finding bugs humans missed, uncovering vulnerabilities buried in code for years, and scanning enormous codebases faster than security teams ever could. Google executives have even called some of these tools a “game changer.” …

You're reading a preview. The full article is published by Android Authority on their website.

Read the full story on Android Authority