Google has temporarily paused product vulnerability submissions to its Open Source Software Vulnerability Reward Program after a surge in automated reports, most of which were invalid. The pause does not affect supply chain reports or pending submissions, and Google plans to provide an update in Q1 2027. #Google #OSSVRP #CloudVRP #PatchRewardsProgram
Keypoints
- Google paused OSS VRP product vulnerability submissions due to a spike in automated invalid reports.
- The pause does not affect supply chain reports or any pending reports already submitted.
- Some Google Cloud product issues may still be reported through Cloud VRP.
- Google is directing researchers to other vulnerability reward programs and the Patch Rewards Program.
- Google plans to revisit the OSS VRP and provide an update in Q1 2027.