# Google pauses new open-source product vulnerability reports: where researchers can still report
> Google paused new OSS VRP product vulnerability submissions on October 1. Supply chain reports and existing cases continue, while some findings may fit separate Cloud, AI or Patch Rewards rules.
By BIG CHANGE Editorial
Published: 2026-10-05T04:59:25.735Z
Updated: 2026-10-05T04:59:25.735Z
Canonical: https://bigchange.ai/blog/google-oss-vrp-product-report-pause-routing-guide

AI-generated conceptual editorial illustration by BIG CHANGE.
Google stopped accepting new product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP) on October 1, 2026. The [current program rules](https://bughunters.google.com/about/rules/open-source/google-open-source-software-vulnerability-reward-program-rules) make the cutoff explicit. Supply chain reports remain welcome, and Google says product reports filed before October 1 are unaffected. For some Google Cloud repositories whose vulnerabilities affect Cloud products, the [Cloud VRP](https://bughunters.google.com/about/rules/google-friends/cloud-vulnerability-reward-program-rules) may still accept a product report.
The pause follows Google's [March 19 rule update](https://bughunters.google.com/blog/ossvrp-rule-updates-2026), when it said it was seeing a surge in AI-generated reports that included incorrect triggers or negligible security impact. In its [October 1 statement](https://x.com/GoogleVRP/status/2105689195180179605), Google described a rise in *automated* submissions, the vast majority of which it said were invalid. The October statement did not identify every automated report as AI-generated. Google promised an update in the first quarter of 2027, without giving a reopening date.
## The big change
The OSS VRP previously accepted qualifying product vulnerability reports for eligible Google open-source projects, subject to project tier and evidence requirements. Since October 1, its new-product-report path is paused. Its supply chain path still accepts findings that could compromise source code or distributed builds, and already filed product reports remain in process. Researchers must now establish the finding's type and product impact before choosing a report form. Google's rules, rather than a repository's Google ownership alone, decide whether another program is available.
## Route the finding before filing
Start with the [OSS VRP rules](https://bughunters.google.com/about/rules/open-source/google-open-source-software-vulnerability-reward-program-rules) and the affected repository's identity and current version. Google says the program covers the latest versions of software in public repositories of Google-owned GitHub organizations, plus selected repositories on other platforms. That scope statement does not make every issue reward eligible.
| Finding | Current route under Google's rules |
| --- | --- |
| A new product vulnerability in Google OSS, such as a flaw in software used by a downstream product | Do not submit it as a new OSS VRP product report during the pause. Check whether its demonstrated impact meets another program's own rules. |
| A weakness that could compromise Google OSS source integrity or distributed build artifacts | Check the OSS VRP supply chain criteria, then use Google's [vulnerability form](https://bughunters.google.com/report) with OSS VRP selected and the repository URL. This intake remains open. |
| A product finding already filed before October 1 | Continue through the existing report. Google says the pause does not affect outstanding reports. |
| A Google Cloud maintained repository with impact on a Google Cloud product or service | Check the [Cloud VRP rules](https://bughunters.google.com/about/rules/google-friends/cloud-vulnerability-reward-program-rules), including the affected product's tier. Google says some such reports may be accepted there; repository location by itself is insufficient. |
| An issue in a Google or Alphabet AI product involving an LLM or other generative AI system as an integral part of the issue | Check the [AI VRP rules](https://bughunters.google.com/about/rules/google-friends/ai-vulnerability-reward-program-rules). Using AI to discover a conventional code flaw does not itself put the flaw in the AI VRP. |
| A proposed security improvement or patch | Check the separate [Patch Rewards Program rules](https://bughunters.google.com/about/rules/open-source/patch-rewards-program-rules) for eligible projects and qualifying changes. It is a patch program, not an alternate intake for the same paused vulnerability report. |
Google's [OSS rules](https://github.com/google/bughunters/blob/main/bughunters/articles/about/rules/open-source/google-open-source-software-vulnerability-reward-program-rules.md) still contain their earlier product-vulnerability acceptance criteria, including OSS-Fuzz reproduction or a merged patch for certain memory corruption findings. Those paragraphs describe requirements for that report type but sit below the newer October cutoff. They are not a way to submit a new OSS VRP product report while the pause applies.
## What a continuing OSS report needs
For a supply chain finding, Google's rules ask researchers to demonstrate an exploitable route to changing Google OSS source, build artifacts or distributed packages. A scenario that only works after a maintainer approves an external pull request is treated as insider risk and considered for credit rather than a supply chain vulnerability reward. Google lists repository and build configuration, release infrastructure and publishing credentials among the relevant surfaces. These are scope descriptions, not permission to test infrastructure belonging to someone else.
This guide is based on Google's program documentation checked October 5, 2026. BIG CHANGE did not test a vulnerability or submit a report. Before submitting, assemble the items Google requests in its [reporting instructions](https://bughunters.google.com/about/rules/open-source/google-open-source-software-vulnerability-reward-program-rules):
1. The repository URL, affected software version and a recent build or configuration to which the finding applies.
2. A concise description of the defect, the conditions needed to trigger it and its security impact. Explain the attack scenario without assuming that a code warning alone proves an exploitable vulnerability.
3. Reproduction instructions and, where practical, a buildable proof of concept. Include relevant output or a crash dump if available. Describe the observed result separately from the impact you infer.
4. The appropriate program and report location. For an OSS supply chain report, select OSS VRP in the Bug Location step of the vulnerability form and specify the repository URL. For Cloud or AI, apply that program's own scope and form instructions.
Google asks researchers to test locally when possible, avoid disrupting other users, and not use automated testing that generates significant traffic. Its [Cloud rules](https://bughunters.google.com/about/rules/google-friends/cloud-vulnerability-reward-program-rules) prohibit testing customer-owned resources. The [AI rules](https://bughunters.google.com/about/rules/google-friends/ai-vulnerability-reward-program-rules) require the reporter to verify the issue and explain an in-scope threat in plain language. These boundaries matter as much as the quality of the write-up.
The program pages are public and state no fee for filing a vulnerability report. A concrete finding, an eligible target and a report that meets the chosen program's rules are the practical prerequisites. Rewards are discretionary and vary by program, project tier and impact. The current OSS reward table lists no new product-vulnerability rewards; it still lists supply chain reward ranges for eligible tiers. Neither submission nor a well-formed report promises payment.
## Why Google changed the intake
Google's March post described AI-assisted research as useful when researchers validate its outputs. It said some submitted reports invented a trigger or identified a coding error without showing a reachable, meaningful security impact. An April update removed rewards or credit for product vulnerabilities and other security issues in lower-tier OT2 and OT3 projects. The October pause goes further for *new* OSS VRP product reports across project tiers. [TechCrunch](https://techcrunch.com/2026/10/04/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions/) also reported the pause. Google's public statements establish the rule change and its stated rationale, but provide no submission counts or independent measure of how many invalid reports used AI.
The immediate task for a researcher is to classify the finding against the live rules, demonstrate a real security consequence, then use only a currently eligible intake. Google says it will update the product-report path in Q1 2027; until then, the October cutoff controls new OSS VRP product submissions.
## Sources & further reading
- [Google OSS VRP rules](https://bughunters.google.com/about/rules/open-source/google-open-source-software-vulnerability-reward-program-rules), current rules checked October 5, 2026. These state the October 1 cutoff, continuing supply chain scope, reporting requirements and reward limits.
- [Google's March 19, 2026 rule update](https://bughunters.google.com/blog/ossvrp-rule-updates-2026), with an April update. This documents Google's earlier, specifically AI-related observations and tier changes.
- [Google VRP's October 1, 2026 statement](https://x.com/GoogleVRP/status/2105689195180179605). The direct X post was not retrievable in our research environment; its text and post ID were located through [a third-party mirror](https://twstalker.com/GoogleVRP/status/2105689195180179605) and its scope was checked against Google's current program rules.
- [Cloud VRP](https://bughunters.google.com/about/rules/google-friends/cloud-vulnerability-reward-program-rules), [AI VRP](https://bughunters.google.com/about/rules/google-friends/ai-vulnerability-reward-program-rules) and [Patch Rewards](https://bughunters.google.com/about/rules/open-source/patch-rewards-program-rules) rules, checked October 5, 2026. Each has separate eligibility and reporting conditions.
## Sources
- [Google Bug Hunters: Streamlining Google’s OSS VRP: Key Rule Updates](https://bughunters.google.com/blog/ossvrp-rule-updates-2026) — Google described a rise in AI-generated reports, explained why it sought stronger evidence of security impact, and later updated project-tier rewards in April. The October pause is stated in the current OSS VRP rules.
- [Google Bug Hunters: OSS VRP rules](https://bughunters.google.com/about/rules/open-source/google-open-source-software-vulnerability-reward-program-rules) — Checked October 5, 2026. Google's current rules state the October 1 product-report cutoff, continuing supply chain scope, reporting instructions and reward conditions.
- [Google VRP (@GoogleVRP) October 1, 2026 statement](https://x.com/GoogleVRP/status/2105689195180179605) — Google's October 1 statement described a rise in invalid automated submissions. We could not retrieve the direct X post; a third-party mirror showed its text and post ID. Google's published OSS rules separately confirm the pause's scope.
- [Google Bug Hunters public GitHub mirror of OSS VRP rules](https://github.com/google/bughunters/blob/main/bughunters/articles/about/rules/open-source/google-open-source-software-vulnerability-reward-program-rules.md) — Google's GitHub copy provides the full current OSS VRP rules, including the date-stamped product-report pause and the continuing supply chain criteria. Checked October 5, 2026.
- [Google Cloud VRP rules](https://bughunters.google.com/about/rules/google-friends/cloud-vulnerability-reward-program-rules) — A Google Cloud maintained open-source repository may qualify when the flaw affects a Cloud product or service. Eligibility and reward tier depend on the Cloud program's own rules. Checked October 5, 2026.
- [Google AI VRP rules](https://bughunters.google.com/about/rules/google-friends/ai-vulnerability-reward-program-rules) — The AI program covers specified issues in Google and Alphabet AI products when interaction with a generative AI system is integral to the issue. It requires reporter verification. Checked October 5, 2026.
- [Google Patch Rewards Program rules](https://bughunters.google.com/about/rules/open-source/patch-rewards-program-rules) — This separate program considers qualifying security improvements and patches to eligible open-source projects under its own project and submission rules. Checked October 5, 2026.
- [TechCrunch: Google froze its open source bug bounty program due to a significant rise in AI submissions](https://techcrunch.com/2026/10/04/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions/) — October 4 reporting provides context on the announcement. Google's published program rules establish the exact reporting routes described here.
- [Tom's Hardware: Google freezes open-source bug bounty program amid flood of invalid AI submissions](https://www.tomshardware.com/tech-industry/artificial-intelligence/google-suspends-part-of-the-oss-vrp-bug-bounty-program-due-to-an-influx-of-invalid-ai-submissions-product-vulnerability-submissions-ended-october-1) — October 3 coverage of the announcement. Google's October statement describes automated submissions; its March program post separately discusses AI-generated reports.
The BIG CHANGE newsletter
The big picture. At your pace.
Recent stories on AI and robotics, the shifts worth watching and practical ideas to use. Choose a daily briefing, weekly digest or monthly perspective.
Sent at 09:00 Belgrade time: daily, Mondays or the first of the month. Your first edition arrives at the next scheduled send after you confirm.
Your privacy, your choice.
Necessary storage supports site security and remembers your choices. Optional Google Analytics stays off until you allow it. You can read every story with necessary storage only. Privacy details