The Pulse
Google Pauses OSS Bug Reports as Invalid Submissions Surge
Google stopped accepting new product vulnerability reports through its Open Source Software Vulnerability Reward Program on October 1, while keeping supply-chain reports and earlier submissions in scope. The company cited a surge in automat

AI.info Team ·
Google has stopped accepting new product-vulnerability reports through its open-source bug bounty, but it is still taking reports about supply-chain threats. The narrow pause, effective October 1, follows what the company described as a sharp increase in automated submissions, most of which were invalid; Google says it will update researchers on the program by the first quarter of 2027.
One reporting channel closes, another stays open
The change applies to product-vulnerability submissions to Google’s Open Source Software Vulnerability Reward Program, or OSS VRP. Google’s October 1 announcement, as reported by Tom’s Hardware, says reports already submitted before that date are unaffected. Supply-chain reports remain eligible, and researchers may still submit product-vulnerability reports through Google’s Cloud VRP for some repositories that affect Google Cloud products.
That distinction matters: Google has paused one category of intake, not shut down the entire OSS VRP. The company directed researchers toward its other vulnerability reward programs or its Patch Rewards Program while it reworks the product-vulnerability portion of OSS VRP. Its Q1 2027 commitment is a deadline for an update, not a promise that submissions will resume by then.
Google had already tightened its evidence rules
The pause follows rule changes Google announced earlier in 2026. For memory-corruption reports involving its highest-priority open-source projects, Google required exact reproduction steps using an existing OSS-Fuzz target or a merged patch. It also stopped offering rewards or credit for product-vulnerability reports involving lower-tier projects, saying its security team would not triage those submissions.
“Recently, we have observed a significant surge in the volume of low-quality and invalid reports submitted to OSS VRP.”
Camille Schneider, information security engineer; Jessica Zhang, technical program manager; and Hayden Blauzvern, software engineer, Google Bug Hunters
In that earlier rule update, Google described AI-generated reports containing incorrect information or hallucinated accounts of how a vulnerability might be triggered. It also warned that a report can point to a genuine coding error and still fail to show meaningful security impact—for example, when the affected code path cannot be reached.
Automation is the stated trigger; AI is part of the context
Google’s October notice, as relayed by Tom’s Hardware, identified a rise in automated submissions and said the vast majority were invalid. The earlier Google post specifically discussed AI-generated reports, but the October wording does not establish that every invalid submission came from an AI tool. The distinction leaves room for a broader mix of automated or poorly validated reports than the phrase “AI flood” alone suggests.
For security researchers, the immediate practical change is clear: new OSS VRP product-vulnerability reports are no longer accepted, while qualifying supply-chain reports and submissions filed before October 1 remain unaffected. Google has not announced new acceptance criteria or a reopening date. Its next stated milestone is an update in Q1 2027.