Google pauses product-vulnerability reports in OSS VRP from October 1 after wave of automated submissions
Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP), effective October 1, 2026. The reason, according to the company itself: a sharp rise in automated submissions, in which "the vast majority are not valid." The pause was announced in a post from Google VRP on X, and it affects one of the industry's most important channels for accountability for flaws in open-source software.
What is actually closed – and what remains open
The pause does not cover all of Google's security reward tools. In the quoted text from the X post, reproduced by Times of India via MSN, it says in translation: "PSA for open source bug hunters. We are temporarily no longer accepting OSS VRP product vulnerability reports. This does not affect OSS VRP supply chain reports, or any outstanding reports" (Times of India via MSN).
In practical terms, that means three important exceptions:
- Supply chain reports under the OSS VRP remain open. Not all types of findings are being stopped, only reports about vulnerabilities in the products themselves.
- Valid reports logged before October 1 will still be processed, according to Times of India's coverage. Existing cases are not being thrown away.
- Vulnerabilities affecting Google Cloud can instead be reported through the separate Google Cloud VRP program, Times of India reports. Google is also encouraging researchers to look for impact across the program's other VRP programs, or to go through the Patch Rewards Program.
It is worth emphasizing what is not happening: This is not a shutdown of Google's entire bug bounty operation, and Q1 2027 is a date for an update – not a confirmed reopening date. TechBooky describes it as a restructuring of the submission framework, with an official progress update expected in the first quarter of 2027 (TechBooky; Newsbytes).
Google's own explanation
In the quoted X post, Google justifies the pause as follows, in translation: "This pause is due to a significant increase in automated submissions, the vast majority of which are not valid. We will continue to reformat and work on this part of OSS VRP, and we are committed to providing an update in Q1 2027" (Times of India via MSN).
It is important to note that Google's own wording is qualitative. The company does not say how many reports are involved, nor exactly what share are invalid – only "the vast majority." One syndicated article (Tom's Hardware content via MSN) refers to "thousands" of low-effort or irrelevant claims from large language models, but that characterization is not tied to any concrete, cited basis and should be treated with caution (Tom's Hardware via MSN). What is certain is that the submissions are automated and that they are overloading security engineers and maintainers of open-source projects.
This is the culmination of a development over several months
The pause does not come out of nowhere. According to TechBooky, Google already tightened the OSS VRP rules in March 2026: Stronger documentation requirements were imposed for certain product vulnerabilities, and rewards were reduced for projects in lower-priority tiers. Google's security team at the time described AI-generated reports with fabricated details and findings of flaws with negligible real impact.
The March intervention was thus an attempt to filter out the noise without closing the door. The October pause suggests the filters were not enough – an escalation from tighter rules to a full stop for one report category.
The pattern extends beyond Google
Google is not alone in experiencing vulnerability intake being drowned in automated noise:
- Linux: Maintainers have, according to Times of India's summary, reported being "completely swamped" by false CVE registrations, after automated AI hunters drove the number of registered vulnerabilities up to record highs of around 2,000 per release. The influx is said to have forced the Linux project to drop support for older network drivers. (The 2,000 figure comes from secondary sources and has not been independently confirmed in this coverage.)
- Intel: The chipmaker recently froze its own bug bounty program, which paid up to $100,000 per finding. But here it is important to distinguish between the official and the attributed: Intel has not itself cited synthetic submissions as the cause. It is industry analysts who widely attribute the freeze to the same type of AI-spam bottlenecks, according to Times of India.
Taken together, this paints a pattern: AI tools make it cheap to generate the appearance of a security report, while the cost of evaluating each report – reading it, reproducing it, rejecting it – remains human. When submissions rise sharply and triage capacity does not, intake systems become overloaded. The irony is that the same models that can help find real flaws also lower the threshold for submitting hundreds of worthless ones.
Open questions
Several key points remain unresolved:
- The scale: Google's statement is qualitative. There is no officially confirmed figure for how many invalid reports triggered the pause.
- Reopening: Q1 2027 is a date for a status update, not a promised reopening. It remains unclear when – or whether – product vulnerability reports will be accepted again in their current form.
- The restructuring: It is not yet known how Google will reorganize the submission process to separate genuine findings from automated noise.
It is also worth noting that one syndicated article gives the start date as "October 1, 2024," which is contradicted by all other sources – including the article's own reference to Q1 2027 – and is obviously a typo. The correct date is October 1, 2026.
What security researchers should do now
For those doing responsible security research on Google's open-source projects, the consequences are concrete:
- Product vulnerabilities in open-source projects cannot currently be submitted via the OSS VRP. Reports already logged and valid will be carried forward.
- Findings affecting Google Cloud can instead go through Google Cloud VRP.
- Supply chain findings under the OSS VRP can still be submitted as normal.
- The Patch Rewards Program remains an option for those who want to be rewarded for the repair work itself.
The biggest uncertainty concerns disclosure timelines. For vulnerabilities that do not fit into the remaining channels, there is currently no official submission route – which in the worst case could force researchers to hold on to findings longer than they should, or to choose riskier disclosure methods. That is one reason Google's promised update in Q1 2027 will be watched closely far beyond the open-source community.

