Google OSS VRP suspension after automated AI submissions flooded the program
Security Tool/Service
Summary
Hide ▲
Show ▼
Google has suspended its Open Source Vulnerability Rewards Program (OSS VRP) until 2027, disrupting a vulnerability-reporting channel for its open-source projects. The pause follows a significant rise in automated submissions that were mostly invalid, reducing the program’s usefulness for researchers. Google says existing reports and supply-chain reports are not affected, and the program will be reformatted before a Q1 2027 update.
Related Happenings
Google OSS VRP pauses product vulnerability submissions after AI-generated report surge
Security Tool/Service
H score12
First: 05.10.2026 11:27
Last: 05.10.2026 11:27
Sources 1
About this happening:
Google temporarily suspended OSS VRP product vulnerability submissions, pausing part of its open-source bug bounty intake after a surge of AI-generated automated reports...
Google OSS VRP pauses product vulnerability submissions after AI-generated report surge
Security Tool/ServiceAbout this happening: Google temporarily suspended OSS VRP product vulnerability submissions, pausing part of its open-source bug bounty intake after a surge of AI-generated automated reports...
Google Chrome 154 security update (108 vulnerabilities)
Security Patch Release
H score27
First: 23.09.2026 13:36
Last: 23.09.2026 13:36
Sources 1
About this happening:
Google released Chrome 154 to the stable channel, patching 108 vulnerabilities including 11 critical-severity bugs across desktop builds. The update matters be...
Google Chrome 154 security update (108 vulnerabilities)
Security Patch ReleaseAbout this happening: Google released Chrome 154 to the stable channel, patching 108 vulnerabilities including 11 critical-severity bugs across desktop builds. The update matters be...
Google’s Chrome security team security patch release for CVE-2026-17650
Security Patch Release
H score16
First: 30.07.2026 12:15
Last: 30.07.2026 12:15
Sources 1
About this happening:
Google released Chrome 151 security patches for Windows, Mac, and Linux, fixing 370 vulnerabilities and seven critical issues. The update includes CVEs CVE-2026-...
Google’s Chrome security team security patch release for CVE-2026-17650
Security Patch ReleaseAbout this happening: Google released Chrome 151 security patches for Windows, Mac, and Linux, fixing 370 vulnerabilities and seven critical issues. The update includes CVEs CVE-2026-...
Google Dialogflow CX Code Blocks shared-runtime isolation security flaw
Vulnerability
H score32
First: 07.07.2026 19:37
Last: 07.07.2026 19:37
Sources 1
About this happening:
Google Dialogflow CX Code Blocks had a shared-runtime isolation flaw that could let one editable agent affect other Code Block-enabled agents in the same Google Cloud pr...
Google Dialogflow CX Code Blocks shared-runtime isolation security flaw
VulnerabilityAbout this happening: Google Dialogflow CX Code Blocks had a shared-runtime isolation flaw that could let one editable agent affect other Code Block-enabled agents in the same Google Cloud pr...
UNC6508 China-linked REDCap espionage campaign
Campaign
H score39
First: 15.06.2026 17:00
Last: 15.06.2026 17:00
Sources 1
About this happening:
UNC6508 ran a China-linked espionage campaign against exposed REDCap servers used by North American medical, academic, and military research networks. The operatio...
UNC6508 China-linked REDCap espionage campaign
CampaignAbout this happening: UNC6508 ran a China-linked espionage campaign against exposed REDCap servers used by North American medical, academic, and military research networks. The operatio...
Timeline
-
05.10.2026 13:30 2 articles · 1h ago
Google OSS VRP suspension after automated AI submissions flooded the program
Initial DisclosureGoogle first suspended OSS VRP after automated report volume overwhelmed the intake process. The program is expected to be reformatted and updated in Q1 2027.
Show sources
- Google Suspends Open-Source Bug Bounty Due to AI Vulnerability Reports — www.infosecurity-magazine.com — 05.10.2026 13:30
- Google Suspends Open-Source Bug Bounty Due to AI Vulnerability Reports — www.infosecurity-magazine.com — 05.10.2026 13:30