Google freezes product flaw submissions to its OSS Vulnerability Reward Program over an influx of invalid AI-driven reports, plans an update by Q1 2027 (Etiido Uko/Tom's Hardware)
Engineers and open-source maintainers reportedly overwhelmed by thousands of sloppy reports — Google has officially suspended product …
Google has suspended product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP) due to an influx of invalid AI-driven reports. The suspension, which took effect on October 1, does not affect product vulnerabilities submitted before that date. Google has encouraged participants to explore other VRP programs and plans to provide an update by the first quarter of 2027.
According to Tom s Hardware, engineers and open-source maintainers were overwhelmed by thousands of sloppy reports. Google will still accept reports covering product vulnerabilities through the Cloud VRP for some Google Cloud repositories impacting Google Cloud products. The suspension also does not affect OSS VRP supply chain reports.
Google is reformatting and working on the OSS VRP program in the meantime. The company made the announcement on October 1 via an official X post. A similar case was reported in Linux, which ended support for older network drivers due to an influx of false AI-generated bug reports.
Brief written by urgent.news from Techmeme, Tom's Hardware — 2 reports on this story. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.