Google is suspending new product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP) starting October 1, 2026. The decision follows a massive influx of bug reports generated by artificial intelligence tools, often low-quality and containing hallucinations. These invalid submissions have overwhelmed security engineers and open source project maintainers who must manually review each report. Reports filed before the cutoff date will continue to be processed normally, and supply chain as well as cloud-related submissions are not affected. Google plans to unveil its reforms in Q1 2027. Other similar programs, such as the Internet Bug Bounty, Intel, and Linux kernel maintainers, have faced the same challenges.
Source: Read the original article

