HOC Shorts
Google officially suspended product vulnerability reports under its Open Source Software Vulnerability Reward Program (OSS VRP).
- The Cause: An overwhelming surge in low-quality, automated “AI slop” and synthetic bug reports flooded security teams, with the vast majority determined to be invalid.
- Scope Exceptions: The pause applies strictly to OSS VRP product vulnerability submissions; supply chain reports and reports via the Google Cloud VRP remain active.
- Next Steps: Google plans to restructure the submission and triage framework, with an operational update scheduled for Q1 2027.
Quick Summary
Google announced an operational freeze on product vulnerability submissions for its flagship Open Source Software Vulnerability Reward Program (OSS VRP). The decision comes as automated, LLM-generated bug reports—often containing hallucinated vulnerabilities or low-effort speculative findings—overwhelmed security triage teams and repository maintainers.
While AI models have significantly accelerated legitimate code auditing, their accessibility has triggered a wave of automated “bug-hunting” scripts submitted en masse by researchers seeking payouts, paralyzing crowdsourced vulnerability management.
Key Details & Program Scope
- The Trigger: Google stated the temporary halt was driven by a “significant rise in agooutomated submissions, the vast majority of which are not valid”.
- What Is Paused: Product vulnerability disclosures targeting Google-maintained open-source projects under the OSS VRP.
What Remains Active:- Supply Chain Disclosures: Supply chain vulnerability reporting under OSS VRP continues unaffected.
- Google Cloud Repositories: Security reports impacting Google Cloud products can still be submitted via the Google Cloud VRP.
- Patch Rewards Program: Proactive contributions improving open-source security postures remain eligible for rewards.
- Timeline: Google will use the pause to redesign its intake verification controls and submission criteria, with an official status update slated for Q1 2027.
Google posted on X,
We are temporarily no longer accepting OSS VRP product vulnerability submissions. This does not impact OSS VRP supply chain reports, or any outstanding reports. As an alternative, we encourage you to find impact across our other VRP programs and submit there instead, or pursue the Patch Rewards Program.
Broader Industry Trend: The “AI Noise” Crisis
Google is not the first major entity to encounter operational friction due to synthetic bug reports. The incident reflects a growing structural challenge across open-source maintainers and bug bounty platforms:
[LLM / Automated Scanner] ──► Generates Speculative / Hallucinated Bug
│
▼
[Mass Submission to Bounty Portals]
│
▼
[Triage Queue Flooded with Low-Effort Noise]
│
▼
[Maintainer Burnout / Program Discontinuation]
- Prior Program Closures: Early-stage examples include the curl project ending its HackerOne bounty initiative after automated AI submissions created severe triage fatigue for its maintainers.
- Platform Interventions: Platforms like HackerOne and Bugcrowd have increasingly implemented strict spam-filtering protocols to penalize researchers submitting hallucinated technical claims, unverified static-analysis outputs, or non-reproducible code snippets.
OSS VRP Status Matrix
| Program Channel | Status | Alternative / Next Steps |
| OSS VRP Product Vulnerabilities | PAUSED | Submissions halted until Q1 2027 update |
| OSS VRP Supply Chain Security | ACTIVE | Continue reporting via standard VRP portal |
| Google Cloud Product Repos | ACTIVE | Submit via Google Cloud VRP channel |
| Open Source Patch Rewards | ACTIVE | Submit defensive hardening patches for reward |
You can check more info Google Open Source Software Vulnerability Reward Program Rules here.