Key facts
- Google has paused its Open Source Software Vulnerability Reward Program (OSS VRP).
- The pause is attributed to a significant rise in automated, AI-generated submissions.
- The majority of these AI submissions were deemed invalid.
- Google engineers and open-source maintainers were overwhelmed by the volume of reports.
- The program is expected to remain paused until the first quarter of 2027.
- Supply chain reports for the OSS VRP remain active.
Google has temporarily suspended its Open Source Software Vulnerability Reward Program (OSS VRP) due to an overwhelming influx of invalid, AI-generated bug reports. The company announced the pause, effective October 1, citing a "significant rise" in automated submissions that were largely invalid and consumed excessive time from engineers and maintainers.
While the program is on hold, Google is encouraging researchers to submit findings through its other bug bounty initiatives. The company plans to use the downtime to restructure the submission framework and expects to provide an update in the first quarter of 2027. The suspension specifically affects product vulnerability submissions; supply chain disclosures under the OSS VRP remain active. Google may also accept certain product vulnerability reports impacting Cloud products through the separate Google Cloud VRP.

