Google has suspended product vulnerability submissions for its Open Source Software Vulnerability Reward Program following an influx of invalid AI-driven reports. The pause went into effect on October 1, with the company promising an update in the first quarter of 2027 while it works to reformat the platform.
Software security is evolving rapidly, but automated noise is creating a bottleneck. When algorithms start hunting bugs at scale, the human gatekeepers tasked with maintaining codebases quickly find themselves drowning in digital detritus.
The Collapse Under Automated Submissions
Engineers and open-source maintainers found themselves completely overwhelmed by thousands of poorly written reports. These submissions claimed to uncover critical software defects, but turned out to be entirely invalid or unexploitable hallucinations generated by large language models. Instead of shipping secure code, maintainers spent precious hours manually validating garbage text.
Tom’s Hardware reported that Google explicitly blamed this exact operational bottleneck for the sudden freeze, stating that the vast majority of automated submissions lacked any technical validity. The barrier to entry for bug hunting dropped to zero once LLMs and automated scripts entered the ecosystem. Consequently, platforms designed to reward genuine security research buckled under sheer volume.
Google Pauses Product Vulnerability Submissions for OSS VRP
The operational shutdown specifically targets product vulnerability submissions within the OSS VRP framework. However, the restrictions do not apply universally across Google’s infrastructure.

- Product vulnerability submissions ended strictly on October 1.
- Reports submitted prior to that cutoff date remain under review.
- Cloud VRP submissions may still be accepted for specific Google Cloud repositories impacting Google Cloud products.
- OSS VRP supply chain reports remain entirely unaffected by the pause.
Participants looking for alternative avenues have been encouraged by Google to redirect their efforts toward other active VRP programs while the core open-source repository rules undergo restructuring.
Broader Industry Strain Across Open-Source Kernels
This vulnerability triage crisis is not an isolated incident confined to a single tech giant. The entire software development ecosystem is grappling with the fallout of unchecked generative AI tools.
Linux maintainers recently reported being completely overwhelmed by Common Vulnerabilities and Exposures finds after AI-powered bug hunters pushed the Linux kernel to a record 2,000 vulnerabilities per release. Similar pressures forced Linux to end support for older network drivers due to an influx of false AI-generated bug reports. Meanwhile, Tom’s Hardware noted that Intel suspended its high-paying bug bounty program—which offered up to $100,000 per flaw—amid widespread industry suspicion that automated reports drove the decision.
What Happens Next for Open-Source Security
Google has committed to providing a formal update on the restructured Open Source Software Vulnerability Reward Program during the first quarter of 2027. Whether stricter cryptographic verification, mandatory human-in-the-loop validation checkpoints, or reputation-gated submission APIs will successfully filter out LLM hallucinations before the program reopens remains entirely unaddressed.