Google OSS VRP pauses product vulnerability submissions after AI-generated report surge
Security Tool/Service
Summary
Hide ▲
Show ▼
Google temporarily suspended OSS VRP product vulnerability submissions, pausing part of its open-source bug bounty intake after a surge of AI-generated automated reports overwhelmed the program. The change leaves supply chain reports and outstanding reports open, limiting the interruption to product vulnerability submissions. Google said it will readjust the OSS VRP and provide an update in Q1 2027.
Related Happenings
Google OSS VRP suspension after automated AI submissions flooded the program
Security Tool/Service
H score11
First: 05.10.2026 13:30
Last: 05.10.2026 13:30
Sources 1
About this happening:
Google has suspended its Open Source Vulnerability Rewards Program (OSS VRP) until 2027, disrupting a vulnerability-reporting channel for its open-source projects. The...
Google OSS VRP suspension after automated AI submissions flooded the program
Security Tool/ServiceAbout this happening: Google has suspended its Open Source Vulnerability Rewards Program (OSS VRP) until 2027, disrupting a vulnerability-reporting channel for its open-source projects. The...
Google Chrome V8 type confusion security flaw (CVE-2026-85046)
Vulnerability
H score36
First: 04.09.2026 10:18
Last: 04.09.2026 10:18
Sources 1
About this happening:
CVE-2026-85046 is a Google Chrome V8 type-confusion vulnerability that was exploited in the wild before Google shipped fixes in 152.0.7977.82/.83 for Windows a...
Google Chrome V8 type confusion security flaw (CVE-2026-85046)
VulnerabilityAbout this happening: CVE-2026-85046 is a Google Chrome V8 type-confusion vulnerability that was exploited in the wild before Google shipped fixes in 152.0.7977.82/.83 for Windows a...
Google Chrome security update for CVE-2026-85046
Security Patch Release
H score40
First: 04.09.2026 10:18
Last: 04.09.2026 10:18
Sources 1
About this happening:
CVE-2026-85046 is a Google Chrome flaw that Google patched in Chrome security updates after it was described as actively exploited in the wild. The release covered...
Google Chrome security update for CVE-2026-85046
Security Patch ReleaseAbout this happening: CVE-2026-85046 is a Google Chrome flaw that Google patched in Chrome security updates after it was described as actively exploited in the wild. The release covered...
Latest development: 23.09.2026 11:29
UTA0565 used fake websites and phishing emails against Asian government entities, masquerading as the Center for American Progress and China Digital Times, to exploit a Chrome-Windows zero-day chain and drop CLEANGULP via the BlueMoon exploit kit. The chain combined CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to escape Chrome's sandbox, achieve remote code execution, and download chrome_cleanup.exe.
Google’s Chrome security team security patch release for CVE-2026-17650
Security Patch Release
H score16
First: 30.07.2026 12:15
Last: 30.07.2026 12:15
Sources 1
About this happening:
Google released Chrome 151 security patches for Windows, Mac, and Linux, fixing 370 vulnerabilities and seven critical issues. The update includes CVEs CVE-2026-...
Google’s Chrome security team security patch release for CVE-2026-17650
Security Patch ReleaseAbout this happening: Google released Chrome 151 security patches for Windows, Mac, and Linux, fixing 370 vulnerabilities and seven critical issues. The update includes CVEs CVE-2026-...
FFmpeg parser/demuxer overflows (multiple vulnerabilities)
Vulnerability
H score36
First: 06.06.2026 10:28
Last: 06.06.2026 10:28
Sources 1
About this happening:
FFmpeg now has 21 confirmed zero-days, creating risk for any product that bundles the media library and processes untrusted video input. The findings include heap and st...
FFmpeg parser/demuxer overflows (multiple vulnerabilities)
VulnerabilityAbout this happening: FFmpeg now has 21 confirmed zero-days, creating risk for any product that bundles the media library and processes untrusted video input. The findings include heap and st...
Timeline
-
05.10.2026 11:27 1 articles · 2h ago
Google OSS VRP pauses product vulnerability submissions after AI-generated report surge
Initial DisclosureGoogle suspended OSS VRP product vulnerability submissions after automated AI-generated reports flooded the intake channel. Supply chain reports and existing cases remain accepted while the program is being adjusted.
Show sources
- Google halts open-source bug bounty program amid AI spam surge — www.bleepingcomputer.com — 05.10.2026 11:27