Skip to content
AMD Faces Backlash Over Bug Bounty Dispute After Critical Vulnerability

AMD Faces Backlash Over Bug Bounty Dispute After Critical Vulnerability

First seen 13 Jun 2026, 05:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 14, 2026 at 05:50 UTC
  • AMD failed to pay a $10,000 bug bounty for a critical vulnerability discovered by a researcher.
  • The vulnerability, CVE-2026-1234, allows for arbitrary code execution and was patched after 124 days.
  • The incident highlights ongoing issues in the relationship between companies and security researchers.

AMD has been criticized for not paying a $10,000 bug bounty to a researcher who discovered a critical security flaw affecting its processors. The vulnerability, identified as CVE-2026-1234, allows attackers to execute arbitrary code and has been present for 124 days before being patched. The researcher reported the issue in January 2026, but AMD's delay in addressing it has raised concerns about the company's commitment to security. The flaw impacts multiple AMD processor models, potentially affecting millions of users worldwide. The incident has sparked discussions about the ethics of bug bounty programs and the responsibilities of companies to their security researchers.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 90d ago How this analysis works

Timeline

2026-01-05
Researcher reports vulnerability
A researcher disclosed a critical security flaw in AMD processors, identified as CVE-2026-1234.
Tech.Yahoo
2026-06-12
AMD patches the vulnerability
AMD released a patch for CVE-2026-1234, addressing the critical flaw after 124 days.
Tech.Yahoo
2026-06-12
Public backlash over bug bounty dispute
AMD faced criticism for not compensating the researcher who reported the vulnerability despite its severity.
Tech.Yahoo

More articles in this cluster (3)