News report

Intel's New Vulnerability Disclosure Program Has No Bug Bounties

Intel's current Intigriti vulnerability disclosure program explicitly offers no bounties, even as Intel's own security pages still advertise rewards of up to $100,000.

On this page
  1. Intel is accepting vulnerability reports without cash rewards
  2. Intel's own security pages have not caught up
  3. Why the incentive change matters for PC security

Intel is accepting vulnerability reports without cash rewards

Intel's current vulnerability-reporting program on Intigriti explicitly says it is a responsible disclosure program without bounties. The program still accepts reports covering maintained Intel-branded processors, server products, wireless and Ethernet hardware, memory and storage, chipsets, graphics, cloud services, firmware and software, but its listed hardware, firmware, software and services assets all show no bounty.

That is a material change for independent security researchers. Intel has historically used paid rewards to encourage outside investigation of its hardware and software stack, including difficult firmware and silicon issues that can demand specialized equipment and substantial research time.

What the current Intel disclosure program says
Program detailCurrent status
Submission platformIntigriti
Cash bountiesNone listed
Hardware reportsAccepted for eligible Intel-branded products; no bounty
Firmware reportsAccepted for eligible Intel-branded products; no bounty
Software reportsAccepted for eligible Intel-branded products; no bounty
Researcher recognitionNamed acknowledgement may be provided
Safe harborProvided when researchers follow the program terms

Intel's own security pages have not caught up

The transition is unusually confusing because Intel's public Bug Bounty Program page still describes a paid program. As of September 19, that page says awards range from $500 to $100,000 and directs researchers to Intigriti as the current provider. A separate Intel security-assurance page likewise says the company has paid millions in bounties and describes cash incentives as part of its vulnerability process.

The destination researchers are actually sent to now says the opposite: no bounties. Intigriti's current program activity shows the Intel Vulnerability Disclosure Program launching on September 17 and receiving submissions on September 18, so the no-bounty portal is not merely a dormant information page.

Why the incentive change matters for PC security

Bug bounties do not determine whether a vendor can fix vulnerabilities, and Intel's PSIRT process remains in place. Intel says PSIRT receives reports from internal and external sources, reproduces potential vulnerabilities, assesses severity and coordinates mitigation and disclosure. Researchers can therefore continue reporting eligible Intel product flaws through the current portal.

The open question is whether removing direct financial incentives changes how much independent effort is aimed at Intel's platform. Intel's own still-live bounty documentation illustrates why that outside channel has mattered: it says 105 of the 231 CVEs Intel addressed in 2020 came through the Bug Bounty Program. That historical figure cannot predict future discovery rates, but it does show that external reports have previously supplied a substantial share of Intel's disclosed security work.

For PC users there is no immediate patch or configuration action attached to this program change. Its significance is upstream: incentives can influence where specialist researchers spend time looking for flaws in processors, firmware, graphics, networking and the software surrounding them. The practical effect, if any, will only become measurable over a longer period.

Sources

Primary and technical sources

These sources support the reporting and analysis above. Current stories are updated when later evidence materially changes the facts.

  1. 01 Intigriti

    Intel Vulnerability Disclosure Program
  2. 02 Intel

    Intel Bug Bounty Program
  3. 03 Intel

    Intel's Approach to Security Vulnerabilities
  4. 04 Phoronix

    Intel Appears To End Its Bug Bounty Program

Related