AI News Feed
Market watch
Cybersecurity

Google Halts OSS VRP Product Vulnerability Submissions After Surge in Automated Reports

Google has temporarily stopped accepting product vulnerability submissions through its OSS VRP after a significant rise in automated reports, many of which it says are invalid, according to Android Authority.

The pause affects product vulnerability reports submitted through OSS VRP. Android Authority did not report when Google might resume accepting those submissions. Google had already warned in March about a massive surge in AI-generated reports, the report said. Those reports included hallucinated bugs and low-impact issues.

Android Authority noted that the timing is hard to ignore. Google has spent much of 2026 praising AI for making bug hunting faster, easier and far more productive. The company's AI agents are finding bugs humans missed, uncovering vulnerabilities buried in code for years and scanning enormous codebases faster than security teams ever could. Google executives have called some of these tools a "game changer."

But the success story has a wrinkle. AI has apparently become so good at helping people find bugs that Google has had to close one of the doors through which those bugs were being reported, according to Android Authority. The search giant described the trigger as a significant rise in automated submissions.

The OSS VRP is a vulnerability reward program. Its temporary closure to product vulnerability submissions means automated reports will not be accepted through that channel for now. Many of the automated submissions Google received were invalid, the company said.

The March warning covered AI-generated reports that included hallucinated bugs and low-impact issues. Those included reports of bugs that did not exist and reports of issues with limited security impact, according to Android Authority. The warning came months before Google paused the OSS VRP submissions.

Google's public statements have highlighted AI's ability to speed up vulnerability discovery. The company has pointed to AI agents that scan large codebases and uncover issues human security teams missed. Executives have described some of the tools as a "game changer." The OSS VRP pause came after the company faced a volume of automated reports.

The pause is temporary, according to Android Authority, but no date for reopening was provided in the report. The report also did not say how many automated submissions prompted the move.