Google Suspends OSS VRP Product Vulnerability Submissions After Invalid AI Reports
Summary
Google has suspended product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP), citing an influx of invalid reports generated with AI. The suspension began on October 1, 2026, and Google said it would provide an update by the first quarter of 2027 while it reformats and works on this part of the program. Reports submitted before October 1 are not affected. Some reports may still be accepted through the Cloud VRP when they concern selected Google Cloud repositories that affect Google Cloud products, and supply-chain reports remain covered by the OSS VRP. The program rewards independent researchers for responsibly reporting security flaws in Google’s open-source ecosystem, including code defects, logic flaws, and design bugs. The article says large language models and automated bug-hunting scripts have reduced the cost of producing reports, prompting thousands of low-effort submissions that claimed to identify vulnerabilities but were invalid or not exploitable. Engineers and maintainers consequently spent substantial time manually checking false reports instead of addressing real vulnerabilities. The article places the decision in a broader industry pattern: Linux maintainers reported being overwhelmed by AI-assisted CVE findings, while Linux kernel releases approached 2,000 vulnerabilities, and Intel suspended a bug bounty program offering up to $100,000 per flaw. Intel did not confirm that AI-generated reports caused its suspension, and the article presents that explanation as expert suspicion rather than an established fact.