On October 1, Google officially suspended the product vulnerability submission channel within its Open Source Software Vulnerability Reward Program (OSS VRP) due to a surge of invalid vulnerability reports generated by AI, which has placed immense pressure on review engineers and open-source maintainers. The company expects to provide further updates in the first quarter of 2027 after realigning the relevant mechanisms.
