Google has stopped accepting new product vulnerability reports through its Open Source Software Vulnerability Reward Program after a surge of automated, AI-generated submissions overwhelmed reviewers. Reports submitted before October 1 remain valid, and researchers are being redirected to other reward programs while Google plans an update in Q1 2027. #Google #OSSVRP #CloudVRP #PatchRewardsProgram
Keypoints
- Google paused new product vulnerability reports in its OSS VRP.
- The change was driven by a flood of invalid, AI-generated submissions.
- Reports submitted before October 1 are still accepted.
- Some Google Cloud repository issues may still be reported through Cloud VRP.
- Google plans to provide a program update in Q1 2027.
Read More: https://www.helpnetsecurity.com/2026/10/05/google-ai-generated-vulnerability-reports-pause/