Find notable cyber news and cases, enriched with sources, timelines, and signals.

Google OSS VRP pauses product vulnerability submissions after AI-generated report surge

Security Tool/Service
First reported
Last updated
Happening score
H score 12
1 unique sources, 1 articles

Summary

Hide ▲

Google temporarily suspended OSS VRP product vulnerability submissions, pausing part of its open-source bug bounty intake after a surge of AI-generated automated reports overwhelmed the program. The change leaves supply chain reports and outstanding reports open, limiting the interruption to product vulnerability submissions. Google said it will readjust the OSS VRP and provide an update in Q1 2027.

Related Happenings

Google OSS VRP suspension after automated AI submissions flooded the program

Security Tool/Service
H score11 First: 05.10.2026 13:30 Last: 05.10.2026 13:30 Sources 1

About this happening: Google has suspended its Open Source Vulnerability Rewards Program (OSS VRP) until 2027, disrupting a vulnerability-reporting channel for its open-source projects. The...

Google Chrome V8 type confusion security flaw (CVE-2026-85046)

Vulnerability
H score36 First: 04.09.2026 10:18 Last: 04.09.2026 10:18 Sources 1

About this happening: CVE-2026-85046 is a Google Chrome V8 type-confusion vulnerability that was exploited in the wild before Google shipped fixes in 152.0.7977.82/.83 for Windows a...

Google Chrome security update for CVE-2026-85046

Security Patch Release
H score40 First: 04.09.2026 10:18 Last: 04.09.2026 10:18 Sources 1

About this happening: CVE-2026-85046 is a Google Chrome flaw that Google patched in Chrome security updates after it was described as actively exploited in the wild. The release covered...

Latest development: 23.09.2026 11:29

UTA0565 used fake websites and phishing emails against Asian government entities, masquerading as the Center for American Progress and China Digital Times, to exploit a Chrome-Windows zero-day chain and drop CLEANGULP via the BlueMoon exploit kit. The chain combined CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to escape Chrome's sandbox, achieve remote code execution, and download chrome_cleanup.exe.

Google’s Chrome security team security patch release for CVE-2026-17650

Security Patch Release
H score16 First: 30.07.2026 12:15 Last: 30.07.2026 12:15 Sources 1

About this happening: Google released Chrome 151 security patches for Windows, Mac, and Linux, fixing 370 vulnerabilities and seven critical issues. The update includes CVEs CVE-2026-...

FFmpeg parser/demuxer overflows (multiple vulnerabilities)

Vulnerability
H score36 First: 06.06.2026 10:28 Last: 06.06.2026 10:28 Sources 1

About this happening: FFmpeg now has 21 confirmed zero-days, creating risk for any product that bundles the media library and processes untrusted video input. The findings include heap and st...

Timeline

  1. 05.10.2026 11:27 1 articles · 2h ago

    Google OSS VRP pauses product vulnerability submissions after AI-generated report surge

    Initial Disclosure

    Google suspended OSS VRP product vulnerability submissions after automated AI-generated reports flooded the intake channel. Supply chain reports and existing cases remain accepted while the program is being adjusted.

    Show sources