Google Freezes OSS VRP Product Bug Reports After AI Slop Flood
TL;DR
- Google stopped accepting product vulnerability reports for its Open Source Software Vulnerability Reward Program on October 1, 2026.
- Supply chain submissions and pre-October 1 reports continue, and Cloud VRP still accepts product bugs for some Google Cloud repos.
- Google says it will share an update on the program's future by the first quarter of 2027.
Google is no longer accepting product vulnerability reports for its Open Source Software Vulnerability Reward Program. The change took effect on October 1, the day Google announced it on X, and the company says it will share an update on the program's future by the first quarter of 2027, according to Tom's Hardware.
Anything filed before October 1 is still being processed. Supply chain submissions, the part of OSS VRP that covers compromised build pipelines and tampered packages, are unaffected. Product bugs can still be sent through the Cloud VRP "for some Google Cloud repos impacting Google Cloud products."
The reason Google gave is "an influx of invalid AI-driven reports." Engineers and open-source maintainers were being buried in reports that claimed to find bugs but turned out to be hallucinations or coding errors with no security impact, spending too much time manually validating code instead of actually fixing real, critical vulnerabilities. The company told researchers to "explore other VRP programs" in the meantime.
This arrives in the middle of a dense run of adjacent coverage on our tracker, with 37 hallucination stories and 200 cybersecurity items logged in the last 90 days, and Anthropic's Mythos tool finding an exploited Rejetto HFS flaw only days ago. The receiving end of the pipeline cracked first.
Originally reported by tomshardware.com
Read the original article →Original headline: Google Freezes OSS VRP Product-Flaw Submissions as AI-Generated Slop Overwhelms Maintainers, Update Due Q1 2027