Hi hackers,
We have temporarily paused new submissions to the Trusted Firmware Bug Bounty program while we review and evolve the program for the changing vulnerability research landscape.
As experienced by other vendors, the increasing use of AI-assisted vulnerability discovery has created new opportunities for security research, but has also led to a significant increase in submissions that do not represent valid security issues. We are taking this opportunity to review the program’s scope and processes so that it can continue to support high-quality security research and effective collaboration between Arm and the research community.
This pause applies only to new submissions to the Trusted Firmware Bug Bounty program. Existing submissions will continue to be processed as normal, and the Arm GPU Bug Bounty program is unaffected.
We expect to complete the review in 2027, at which point we will share an update on the future scope and operation of the Trusted Firmware Bug Bounty program. Our focus during this period will be on adapting the program to the rapidly evolving capabilities of AI-assisted security research while continuing to encourage rigorous, reproducible and impactful vulnerability research.
The Trusted Firmware Security Incident Handling Process remains unchanged. Whilst not eligible for a bounty, any vulnerabilities in Trusted Firmware projects may be reported by following the documented process: https://general.docs.trustedfirmware.org/en/latest/security_center/incident_handling_process.html
Arm remains committed to bug bounty and to constructive engagement with security researchers. We expect the lessons from this review to help us evolve our approach to bug bounty as vulnerability research and AI-assisted security tooling continue to develop.
Thanks for all your engagement so far and for bearing with us while we undertake this work,
Arm PSIRT
Hi Hackers!
As part of our regular program and prioritisation updates, we are reducing the bug bounty scope of the Mbed TLS project to only include attacks against the TF-PSA-Crypto submodule. This helps ensure that we are targetting the area most important to Arm.
Thanks for all the work you've been doing. We look forward to receiving all your reports!
Arm PSIRT
We love enthusiastic security research, and the community response we’ve had to our Trusted Firmware Bug Bounty Program has been great.
Lately, our triage team has been meeting a few too many AI-generated reports that are very difficult to triage. These reports often rely on flawed assumptions, internal-only functions or a lack of real security impact.
To help us focus on genuine, reproducible findings, all reports must now include an end-to-end proof of concept that:
- runs on a TF supported platform (TF-A, TF-M and OP-TEE only; emulated environments are fine)
- reproduces the issue on a correctly implemented system
- demonstrates a meaningful security impact (not just compliance or potential for hardening)
AI has been a game-changer for vulnerability discovery, but an LLM-generated report isn’t enough on its own. Please ensure you always validate and triage your findings before submitting them, and always check your PoC to make sure our team can follow the same path you did.
Thanks for helping us keep the signal high and the bugs real. Happy hunting!!