← Back to news
SecurityWeek5 Oct 2026 · 2 min read

Google Pauses Open Source Product Bug Reports Citing Surge in Invalid Automated Submissions

Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP), citing a sharp increase in automated submissions that it...

Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP), citing a sharp increase in automated submissions that it says are largely invalid.

The company announced the change on October 1, stating that the pause applies only to reports involving product vulnerabilities. Supply chain vulnerability submissions and reports filed before the cutoff remain unaffected, according to Google.

Alternative reporting options remain

Google said some findings involving Google Cloud repositories and Cloud products may still qualify for reporting through its Cloud Vulnerability Reward Program. The company encouraged researchers to assess whether discoveries fit within the scope of its other reward programs.

Researchers can also use Google’s Patch Rewards Program, which pays contributors for security improvements made proactively to eligible open source projects. Google said it is reviewing how the OSS VRP handles product vulnerability reports and plans to provide an update during the first quarter of 2027.

Automation changes bug bounty operations

The OSS VRP was introduced in 2022 to reward researchers who identify flaws in Google-managed open source software. The current suspension reflects a wider challenge for vulnerability disclosure programs: automated and AI-assisted tools can generate large volumes of potential findings, increasing the effort required to separate actionable bugs from duplicates, false positives, and poorly supported reports.

Google has already adjusted other reward programs in response to this trend. Earlier this year, it changed aspects of its Chrome and Android bounty structures, placing greater emphasis on reports with clear evidence of exploitability and on vulnerability classes that may be more difficult for automated tools to uncover. The company also raised the maximum reward for certain high-impact Android exploit chains.

  • Product vulnerability reports to the OSS VRP are temporarily paused.
  • Supply chain reports and submissions made before October 1 are not affected.
  • Eligible Cloud-related findings may be reportable through Google’s Cloud VRP.
  • Google expects to share further details on the program’s future in Q1 2027.

Other bug bounty operators have faced similar pressure as AI-assisted research accelerates the pace of submissions and strains the capacity of maintainers and security teams to validate reports and develop fixes.

Share this article:TwitterLinkedIn