-
Google has paused new product vulnerability submissions to its OSS VRP after a surge in low-quality automated reports.
-
Researchers can still use Google’s Patch Rewards Program, Cloud VRP, and other security reporting channels.
-
Google plans to revise the OSS VRP and provide another update during the first quarter of next year.
Google has put a halt on accepting incident reports as part of the Open Source Software Vulnerability Rewards Program (OSS VRP). This decision came due to a surge in automated reports that do not point out valid security flaws.
The OSS VRP rewards researchers who find flaws in the open-source projects of Google. However, the company now wants to adjust the program after AI-generated reports created a heavier review workload for its security teams.
Google Faces a Wave of Automated Security Reports
The tech giant launched the OSS VRP in 2022, which aims to make open-source software safer for its ecosystem. This protection includes projects such as Golang, Angular, Bazel, Protocol Buffers, and Fuchsia. Also, it extends to some essential third-party components and vulnerabilities related to repository setups, including GitHub Actions, application configurations, plus access control rights.
In the beginning, the program offered from $100 and up to $31,337 in rewards. Google designed those rewards to encourage researchers to find flaws with serious effects on the software supply chain. However, the company now faces a different challenge. AI tools can produce vulnerability reports at a much faster rate than human researchers.
Google says most recent automated submissions did not contain valid security findings. Some alerts can register real issues in the code but have no significant impact in terms of security. This became a problem in itself since it requires the work of security teams and takes time during the screening of the alerts.
Google has already changed its OSS VRP rules to address this trend. Earlier updates introduced stricter evidence requirements for certain vulnerability categories.
AI is Changing How Researchers Find Vulnerabilities
AI has changed the speed and scale of security research. It provides various tools for examination of source code & description of problems with it. Also, it suggests the appropriate solutions plus shows possible paths of attack. However, if the method is quick, that does not ensure success.
AI agents are also moving beyond vulnerability research into offensive activity, with autonomous AI agents deploying custom ransomware to target AI models, detailing how an autonomous agent was used to deploy ransomware against AI systems. For example, an AI system may produce a very convincing report, but will not demonstrate whether it is possible for an attacker to exploit the vulnerability.
Google highlighted this problem in its earlier OSS VRP updates. The company noted a rise in reports containing incorrect details or unrealistic vulnerability scenarios. Some submissions also pointed to coding errors with little practical security impact.
For example, a report might identify a buffer overflow but fail to show that attackers can reach the affected code. Thus, Google now aims for stronger proof from researchers, i.e., reliable reproduction of steps, OSS-Fuzz results, or a merged patch.
The company has created the related project tiers in order to distinguish the high-importance open-source projects from the less crucial ones. This approach helps its teams focus on vulnerabilities that could create greater real-world damage.
The wider bug bounty programs of Google show the same shift. The company increasingly values clear evidence and demonstrated impact instead of long technical reports alone.
Researchers Still Have Other Google Programs
The pause does not close every path for security researchers who want to work with Google. Researchers can still report issues through several other vulnerability reward programs. The Patch Rewards Program of Google remains available for researchers who create security improvements for open-source software. The company also continues to accept relevant vulnerabilities through its Cloud VRP.
The OSS VRP itself also continues to cover certain supply chain security issues. Google says those reports remain important because attackers can use compromised build systems or source repositories to affect many users. In addition, credential leaks remain a priority under the program. Exposed credentials with write access can create serious risks for open-source projects and their users.
Google has not abandoned its broader bug bounty strategy. Instead, the company appears to be changing how it handles the growing volume of automated security research. That change follows a wider industry concern. AI helps make the process easier for researchers as it helps identify vulnerabilities, but it also produces thousands of weak & false reports.
For security teams, that creates a new balancing problem. They must gain the benefits of AI without allowing low-quality submissions to overwhelm human analysts.
Google Plans Further Changes to the OSS VRP
Google says it plans to rework the OSS VRP and provide more details about the next changes. The company expects to give another update during the first quarter of 2027. The current pause affects product vulnerability submissions made from October 1 this year. Existing reports and supply chain reports remain outside the scope of the suspension.
The decision of Google also comes after years of major spending on vulnerability research. Its bug bounty programs have rewarded thousands of researchers since the company launched its first VRP in 2010.
The security program of the company records shows more than $81.9 million in total rewards. Researchers received over $17 million in 2025 alone. Therefore, the company still believes that external researchers are a crucial element of security for its systems. The challenge now involves separating useful research from automated noise.
Meanwhile, Google continues to adjust other VRPs for the AI era. Its Android and Chrome programs have also moved toward stronger proof of real security impact. The latest OSS VRP suspension shows how rapidly AI has developed in vulnerability research. It hints that in the future, bug bounty programs will give priority to verification, evidence of exploitation, and meaningfully applicable solutions.