This guy's experience reporting a bug to Google reminds me of mine: Me: Here's a bug in Google Sheets that exposes deleted content to third parties. Google: Not a bug. Working as expected, closing issue. Me: Really? I was personally harmed by this bug while using the application. Google: Actually, it is a bug but it's a longtime known issue, therefore you are not eligible for bug bounty. Closing issue.
That is, to a T, almost identical to my experience reporting a vulnerability to Google too. Me: Here's a bug in Gmail that allows spoofed email to scrub DKIM failures and appear legitimate Google: "Won't fix (Intended Behavior)" Me: Really? Google intends to allow spoofed email to appear legitimate in its interface? Google: Actually, it's a known issue
For both you hear nothing for about 10 weeks, then it is either closed as "expired", or "won't fix".
Last time I checked, both vulnerabilities still exist.