Google has temporarily suspended its product vulnerability submissions within the Open Source Software Vulnerability Reward Program (OSS VRP) as of October 1, 2026. This action comes in response to a dramatic influx of automated bug reports, most of which were invalid. Google plans to provide updates in the first quarter of 2027. The pause applies only to new product vulnerability disclosures; supply-chain flaws, pending reports from before October 1, and certain issues reported through the Google Cloud Vulnerability Reward Program remain under review.
Why the Pause Happened
The driving issue behind this suspension is a “significant rise” in AI-generated submissions that fail validation. These reports often include fabricated exploit paths, incorrect assumptions about the behavior of source code, or claims that vulnerable functions are reachable when they are not. Such flawed inputs increase the workload for security engineers and maintainers needed to triage them efficiently.
Earlier rule changes in OSS VRP had already cautioned researchers about these risks. Google has observed AI-generated submissions with false triggering conditions and “hallucinations” about how vulnerabilities might be exploited. In response, it has begun tightening evidence requirements—especially for memory corruption issues—within high-priority projects.
Scope of OSS VRP & Remaining Accessible Channels
OSS VRP covers code maintained in public repositories owned by Google, including repository settings, build systems, GitHub Actions workflows, access controls, cryptographic signing keys, and more. The highest premiums go to supply-chain compromise vulnerabilities—those that allow attackers to tamper with build artifacts, manipulate source code, or exploit package registries. These still need to show realistic, exploitable paths—not just theoretical risks.
Rewards vary by project priority. Flagship (OT0) projects can bring in roughly $3,133.70 to $31,337 for top supply-chain issues. OT1 projects can earn between $1,337 and $13,337, while standard OT2 projects qualify for $500 to $3,133.70. Lower priority OT3 repositories are not eligible for financial rewards. Importantly, product vulnerabilities such as memory safety flaws, sanitizer failures, insecure defaults, and path traversal attacks are among the categories now paused.
Meanwhile, Google is redesigning the intake process for product vulnerabilities, and directing researchers toward its other VRP initiatives and Patch Rewards Program in the meantime.
What this means: The move marks an important inflection point in how tech giants are adapting bug bounty programs to deal with AI-induced noise. Balancing openness with quality is becoming tough. Going forward, researchers will need to write more thorough, evidence-rich reports: reproducible proof-of-concepts, exact reproduction steps, clear impact analysis, version details, reachable attack paths, and crash data where possible. As dependence on generative tools grows, so does the need for rigorous validation.