Particle.news

Google Pauses OSS Product Vulnerability Submissions

Automated, largely invalid AI-generated reports overwhelmed human reviewers, prompting Google to redesign the program with an update due in Q1 2027.

Overview

  • The pause began on October 1, 2026, and Google will continue to process reports filed before that date while keeping supply-chain reports open.
  • Google said a large volume of automated submissions included hallucinated or negligible-impact findings that required time-consuming manual triage and were mostly invalid.
  • The suspension applies only to OSS VRP product vulnerability reports; some Cloud-related product reports may still be accepted and researchers are being directed to Cloud VRP, Patch Rewards, or other Google VRPs.
  • The move follows months of earlier steps to raise evidence requirements in March 2026 and mirrors actions by other projects and programs such as curl, the Internet Bug Bounty, Linux maintainers, and Intel that faced similar AI-driven report floods.
  • Google says it will reformat how the OSS VRP validates and routes submissions and will publish details in Q1 2027, a change that could shift rewards toward merged fixes and reduce the burden on small open-source maintainers.