Tom’s Hardware coverage (October 2026) of Google OSS VRP product vulnerability submission pause.

Google suspended product vulnerability submissions to Open Source Software Vulnerability Reward Program effective October 1, 2026, citing influx of invalid AI-driven reports. Official X post October 1; update promised Q1 2027.

Scope: does not affect pre-October-1 submissions or supply-chain reports. Some Google Cloud product vulnerabilities may still route through Cloud VRP for select repositories.

OSS VRP incentivizes researchers to find security flaws in Google’s open-source ecosystem — traditionally requiring skilled manual analysis. Rise of LLM-assisted automated bug-hunting scripts collapsed submission cost, producing thousands of poorly written invalid or hallucinated reports.

Impact: Google engineers and open-source maintainers spending excessive time validating non-exploitable findings instead of fixing real vulnerabilities.

Industry parallel: cURL discontinued bug bounty January 2026; Linux driver maintenance affected by false AI reports.