Google announced on Oct. 1 that it is suspending product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP). The pause is temporary and will stay in place while the company deals with a surge of invalid reports that were generated by artificial‑intelligence tools. Google said participants can still submit bugs to other VRP programs and promised an update on the situation by the first quarter of 2027.
What triggered the suspension?
The company noticed a large number of submissions that appeared to be automatically created by AI and did not contain valid security findings. These low‑quality reports clogged the review process and made it harder for engineers to focus on real bugs. To protect the program’s effectiveness, Google chose to halt new product submissions until it can redesign the intake workflow.
Why it matters
For security researchers, the pause means they must submit open‑source bugs through other reward programs for now, which could slow down payouts for valid findings. For developers, the short‑term gap may reduce the number of quick fixes for open‑source components they rely on. Google has not said how long the suspension will last beyond the promised 2027 update.