Google has stopped accepting new product vulnerability reports through its Open Source Software Vulnerability Reward Program after a sharp increase in automated submissions, most of which the company says are invalid. The pause took effect October 1 and leaves supply-chain reports and outstanding submissions unaffected.

The company plans to revise this part of the program and provide an update in the first quarter of 2027. That commitment sets a date for an update, rather than a deadline for reopening submissions. Google is directing researchers toward its other vulnerability reward programs and its Patch Rewards Program.

The revised rules preserve another route for some product flaws. Reports involving certain Google Cloud repositories that affect Google Cloud products may still be accepted through the separate Cloud VRP. Product vulnerability reports filed before October 1 continue to be handled under the existing process.

Google’s October statement describes the problem as automated submissions. An earlier rule-change announcement explicitly identified AI-generated reports containing incorrect descriptions of how a vulnerability could be triggered. It also described reports that identified real coding errors but had negligible security impact or concerned code that could not be reached.

In that March announcement, Google said researchers needed to validate AI outputs during their work. The company introduced project tiers and raised the evidence requirements for certain memory-corruption reports. For flagship and important projects, those reports required exact reproduction steps using an existing OSS-Fuzz target, or a patch already accepted into the repository.

An April update removed monetary rewards and credit for product vulnerabilities and other security issues in standard and low-priority projects. Google also said its security team would no longer triage those product reports. The October pause extends to the product-vulnerability category across the OSS program.

Supply-chain submissions concern the integrity of source code, build systems and distributed packages. Google’s rules list examples such as flaws permitting unauthorized changes to repository branches, compromised release infrastructure and exposed package-publishing credentials. The rules require researchers to demonstrate exploitability; a vulnerability that depends on a maintainer first approving the attack receives different treatment.

Google has separately introduced Gemini 4 Argon for vetted cyber defenders, giving trusted users access while it develops safeguards for broader distribution. Nvidia has also introduced controls for monitoring and restraining AI agents, including a reference design for a watchdog outside an agent’s host processor.

For researchers submitting eligible OSS reports, Google’s rules request a buildable proof of concept against a recent build, reproduction instructions, affected-version information and an explanation of the attack’s security impact.

Sources: Google VRP, Google Bug Hunters, Google Bug Hunters

–
By the Control Plane Editorial Team