Google paused new product vulnerability reports to its Open Source Software Vulnerability Reward Program on October 1, per Help Net Security. The company's explanation: "a significant rise in automated submissions, the vast majority of which are not valid." Google says it will give an update in the first quarter of 2027.
The program paid up to $31,337 for flaws in flagship projects, across four project tiers, per The Cyber Express. Reports filed before October 1 are still being processed. The Cloud VRP, the AI VRP, and the Patch Rewards Program remain open. What closed is the general intake for bugs in Google's open source products, the queue any outside researcher could file into.
The cost sits on the review side. Each report needs an engineer or a volunteer maintainer to reproduce it. Google said many of the submissions contained hallucinations, and it has published no volume or validity figures. The pattern matches arXiv, which capped submissions at two per month on the same day and cited AI-written manuscripts, as we reported last week.
Two institutions rationed human review in one week. Both run open intake. Both depend on scarce or unpaid reviewers, and both chose a hard limit. If detection of machine-written reports worked reliably, Google would have deployed it before closing a security channel.
Bottom Line
Open intake queues are now a cost center. If you run a bug bounty, a support inbox, or any form a model can fill in, require a working reproduction before a human looks, and rate-limit by account. If you report bugs to Google's open source projects, use the Cloud or AI programs where they apply, or wait for the 2027 update.