跳到主要內容

Google OSS VRP評測:AI假漏洞報告逼停賞金計畫 | Google OSS VRP Review: AI Slop Halts Bug Bounty

By Kit 小克 | AI Tool Observer | 2026-10-05

🇹🇼 Google OSS VRP評測:AI假漏洞報告逼停賞金計畫

Google OSS VRP(開源軟體漏洞獎勵計畫)宣布從2026年10月1日起全面暫停受理「產品漏洞」類型的AI漏洞報告投稿,原因是近期湧入大量由AI生成、內容卻是幻覺的假漏洞報告,資安審查人員大半時間都花在證明這些報告不成立,而不是真的在修漏洞。這起事件讓「AI灌水」第一次具體衝擊到第一線資安營運,也是目前開發者社群最熱議的話題之一。

什麼是Google OSS VRP?為什麼暫停收產品漏洞報告?

Google OSS VRP是針對開源專案資安漏洞的懸賞計畫,資安研究員回報漏洞可領取獎金。Google官方部落格證實,自10月1日起暫停受理新的產品漏洞類報告,原因是近期多數投稿都是AI生成、內容幾乎不成立,而今年4月已先對低等級報告停發獎金,仍擋不住AI灌水的速度。

AI灌水漏洞報告有多誇張?

只要寫一支腳本把LLM指向任何一個開源repo,幾分鐘內就能產出一份看起來很專業的AI漏洞報告:有嚴重度分級、有完整攻擊情境描述,甚至附上「概念驗證」(PoC)程式碼——問題是那段PoC往往根本跑不起來,漏洞也不存在。每一份報告都得有人實際重現、確認、再寫信解釋為什麼不成立才能結案,這些時間原本該花在真正的漏洞上。

  • 規模問題:不是少數幾封,而是大量自動化產出,遠超過人力審查速度
  • 說服力問題:格式、用語、嚴重度評級都模仿真實報告,很難一眼辨別真假
  • Google的應對:4月先對低等級報告停發獎金,10月直接暫停整個產品漏洞類別

暫停會持續多久?開發者和資安研究員該怎麼辦?

Google表示會在2027年第一季前公布更新方案,重新設計審查流程。10月1日前送出的報告不受影響,供應鏈(supply chain)類報告也維持正常受理,真正的資安研究員目前建議改走Google Cloud VRP或Patch Rewards Program等其他管道投稿。

Kit小克的實測心得

這件事對任何想靠AI寫漏洞報告賺外快的人是個警訊:AI很會寫得「像真的」,但不會自己檢查「是不是真的」。如果你是開發者,這其實也是提醒——用AI輔助找漏洞沒問題,但送出前自己動手重現一次,不然名聲會先壞掉。

好不好用,試了才知道。


🇺🇸 Google OSS VRP Review: AI Slop Halts Bug Bounty

Google has fully paused product-vulnerability submissions to its Google OSS VRP (Open Source Software Vulnerability Reward Program) as of October 1, 2026, after a flood of AI-generated vulnerability reports buried maintainers in hallucinated findings. It's the clearest sign yet that "AI slop" has moved from an online joke into a real operational problem for security teams.

What Is Google OSS VRP, and Why Did It Pause Bug Reports?

Google OSS VRP pays security researchers who find real vulnerabilities in open-source projects. Google's own bug-hunters blog confirms it stopped accepting new product-vulnerability reports starting October 1, because most recent submissions were AI-generated and simply invalid — and an earlier April 2026 move to cut rewards for low-tier reports wasn't enough to stop the flood.

How Bad Are the AI-Generated Vulnerability Reports?

Anyone can point an LLM at a repo with a short script and get a polished-looking vulnerability report in minutes — complete with a severity score, an attack narrative, and a "proof of concept" that usually doesn't actually run. Every one of them still has to be read, reproduced, and formally rejected before it can be closed, and that's time maintainers aren't spending on real bugs.

  • Scale: not a handful of bad reports, but an automated flood that outpaces manual review
  • Believability: formatting, tone, and severity ratings mimic real reports closely enough to slow triage
  • Google's response: cut rewards for low-tier reports in April, then paused the entire product-vulnerability category in October

How Long Will the Pause Last, and What Should Researchers Do?

Google says it will share an updated process by Q1 2027. Reports filed before October 1 are unaffected, supply-chain vulnerability reports still go through normal review, and researchers with genuine findings are pointed toward the Google Cloud VRP or the Patch Rewards Program in the meantime.

Kit's Honest Take

If you were hoping to farm bounty money by pointing an LLM at random repos, that door just closed — AI is great at sounding right, not at checking whether it is right. For working developers, the lesson is simpler: use AI to help hunt for bugs, but reproduce the finding yourself before you submit it, or your reputation takes the hit instead of your wallet.

好不好用,試了才知道。

Sources / 資料來源

常見問題 FAQ

Google OSS VRP是什麼?

Google OSS VRP是Google針對開源軟體漏洞提供獎金的資安懸賞計畫,資安研究員回報並驗證漏洞後可領取獎勵。

Google為什麼暫停受理產品漏洞報告?

因為近期湧入大量AI生成的假漏洞報告,內容多為幻覺或無實際影響,審查人力被大量消耗在證明報告無效,而非修復真正的漏洞。

暫停從什麼時候開始、會持續多久?

暫停自2026年10月1日生效,Google預計在2027年第一季前公布更新後的審查流程。

10月1日前送出的漏洞報告還有效嗎?

有效,10月1日之前送出的產品漏洞報告不受影響,供應鏈類漏洞報告也維持正常受理。

資安研究員現在該怎麼投稿漏洞?

目前建議改走Google Cloud VRP或Patch Rewards Program等其他管道,並避免單純用AI生成報告就直接送出。

延伸閱讀 / Related Articles


AI 工具觀察站 — 每日精選 AI Agent 與工具趨勢
AI Tool Observer — Daily curated AI Agent & tool trends

留言

這個網誌中的熱門文章

Google Ironwood TPU v7 推理專用晶片解析:效能追平 NVIDIA、成本低 44%,AI 晶片戰爭正式開打 | Google Ironwood TPU v7 Explained: Matching NVIDIA Performance at 44% Lower Cost — The AI Chip War Heats Up

Claude Code 實測:AI 幫你寫程式到底行不行? | Claude Code Review: Can AI Really Code for You?

Cursor vs GitHub Copilot vs Claude Code:AI 程式助手大比拼 | AI Coding Assistants Compared: Cursor vs GitHub Copilot vs Claude Code