Google has temporarily closed its Open Source Software Vulnerability Reward Program (OSS VRP) to new product vulnerability submissions, citing a sharp rise in automated reports that are overwhelmingly invalid. The pause took effect on October 1 and was announced via a post on X.

“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” Google said. The restriction applies only to product vulnerabilities affecting open source projects such as Go, Angular, and Protocol Buffers. Reports of supply chain compromises remain in scope, and any product vulnerability submitted before October 1, 2026 will still be processed.

Google noted that some product vulnerability reports tied to Google Cloud repositories may still qualify under the separate Cloud VRP. The company is directing researchers toward its other reward programs for impact assessment, and is pointing to its Patch Rewards Program, which compensates contributors for proactively hardening open source security rather than just finding flaws.

Part of a Broader Industry Response

Google said it will keep refining the OSS VRP’s structure and plans to provide an update in the first quarter of 2027. Launched in 2022, the program has historically paid researchers for vulnerabilities discovered in Google’s open source codebases.

The move follows changes Google made in May to its Chrome and Android reward programs in response to growing use of AI tools for vulnerability discovery. Standard Chrome payouts were reduced as Google shifted toward rewarding concise reports with concrete proof of exploitability. For Android, the company said it would prioritize bug classes that are harder for AI tooling to find, while raising the top reward for a zero-click Pixel Titan M exploit with persistence from $1 million to $1.5 million.

Google is not alone in confronting this problem. In March, the Internet Bug Bounty program run by HackerOne paused new submissions, saying the speed and volume of AI-assisted vulnerability discoveries had outpaced the open source community’s capacity to triage and fix them.

For security researchers, the practical takeaway is clear: low-effort, AI-generated submissions without verifiable proof of concept are increasingly likely to be rejected or ignored outright, as vendors recalibrate reward structures to filter out noise and prioritize substantiated findings.