Safety·EASYHUB JOURNAL
Google pauses OSS VRP product-vulnerability submissions after automated reports surge and most prove invalid

What changed
TechCrunch reported on October 4 that Google had paused new product-vulnerability submissions to its Open Source Software Vulnerability Rewards Program effective October 1. Google said automated submissions had risen significantly and the vast majority were invalid; outstanding reports and supply-chain submissions remain unaffected. The company plans to rework this part of the program and provide an update in Q1 2027.
- Original title
- Google froze its open source bug bounty program due to a 'significant rise' in AI submissions
- Source
- TechCrunch · techcrunch.com
- Topic
- Safety
- Source month
- 2026-10
This is a concise EasyHub summary of the linked source, not the full report or original reporting. Availability and preview conditions are described in the summary and original.
Summary page published · Updated · Editorial information