Overview
- Google paused new product vulnerability submissions to its Open Source Software Vulnerability Reward Program on October 1, 2026, while continuing to process reports filed before that date.
- The freeze excludes OSS VRP supply‑chain reports and allows some Cloud‑impacting reports to be submitted through Google’s Cloud VRP.
- Google attributed the action to a surge of automated, AI‑generated reports that often contained hallucinated or low‑impact findings and that created a heavy manual triage burden for security teams and maintainers.
- The company is directing researchers to other reward channels such as its Patch Rewards program and other VRPs and has pledged to publish a reworked OSS VRP framework in Q1 2027.
- Industry peers including the curl project, Intel, the Internet Bug Bounty and Linux maintainers have taken similar steps, raising questions about shifting incentives toward verified fixes and about funding to help volunteer maintainers handle verification work.