close

Samsung Mobile Security
Cookie Policy

Updated on Jan 17, 2022

This Cookie Policy describes the different types of cookies that may be used in connection with Samsung Mobile Security website which is owned and controlled by Samsung Electronics Co., Ltd (“Samsung Electronics”). This Cookie Policy also describes how you can manage cookies.

It’s important that you check back often for updates to the Policy as we may change it from time to time to reflect changes to our use of cookies. Please check the date at the top of this page to see when this Policy was last revised. Any changes to this Policy will become effective when we make the revised Policy available on our website.

Samsung Electronics has offices across Europe, so we can ensure that your request or query will be handled by the data protection team based in your region. If you have any questions, the easiest way to contact us is through our Privacy Support Page at https://www.samsung.com/request-desk.

You can also contact us at:

European Data Protection Officer
Samsung Electronics (UK) Limited
Samsung House, 2000 Hillswood Drive, Chertsey, Surrey KT16 0RS

Cookies

Cookies are small files that store information on your computer, TV, mobile phone, or other device. They enable the entity that put the cookie on your device to recognize you across different websites, services, devices, and/or browsing sessions.

We use the following types of cookies on this website:

Essential Cookies: enable you to receive the services you request via our website. Without these cookies, services that you have asked for cannot be provided. For example, these enable to identify users and provide proper service for each user. These cookies are automatically enabled and cannot be turned off because they are essential to enable you to browse our website. Without these cookies this Samsung Mobile Security website could not be provided.

Cookie Domain Purpose
JSESSIONID security.samsungmobile.com to keep login session
lastActivityTime security.samsungmobile.com to save the user's last activity time to automatically logout after 30 minutes of inactivity

Managing Cookies and Other Technologies

You can also update your browser settings at any time, if you want to remove or block cookies from your device (consult your browser's "help" menu to learn how to remove or block cookies). Samsung Electronics is not responsible for your browser settings. You can find good and simple instructions on how to manage cookies on the different types of web browsers at http://www.allaboutcookies.org.

Go straight to the menu Go straight to the text

Security Post

Announcement

Annual Report in 2024

Jasper Park, Lead of Samsung Project Infinity at Samsung Mobile Security
  1. We are pleased to announce the release of the 2024 Annual Report for Samsung Mobile Security Rewards Program, following last year's publication.
  2. This report highlights the program's continued growth and progress, sharing our achievements with our valued community. While the 2023 Annual Report was released later than anticipated, we aimed to prepare this year's report earlier. However, we apologize for its delayed release and we will strive to deliver the report even earlier next year.
  3. We sincerely appreciate security researchers and communities, our cherished friends. Your support and feedback are the most crucial driving forces behind the program's continuous development. In 2024, thanks to your valuable contributions, we were able to make our products and services even safer.
  4. As a result, the program's total annual rewards exceeded $1 million for the first time in its history. While we still have a long way to go, this reflects our commitment to continuous improvement and growth.
  5. We look forward to continuing this journey together and encourage our friends to keep sharing your insights and expertise. Your contributions are invaluable, and we are grateful for your collaboration.
  6. Our goal for 2025 is to double the number of high-impact reports and further enhance our collaboration with the community.
Review of 2024
  1. Review of 2024
  2. Since launching our Rewards Program in 2017, we have paid out over $6,000,000 rewards to date.
  3. In 2024, we awarded $1,029,380 in total to 105 researchers, marking the program's first annual reward of $1 million.
  4. We are deeply grateful for your contributions.
    • A total of $1,029,380 was awarded to 105 researchers.
    • Yifei Xie holds the record for the highest cumulative reward.
    • hackpotato received the highest single report reward.
  5. Last August, we introduced the ISVP and Bonus Reward programs, offering various rewards for different targets, including a maximum reward of $1M, along with additional bonuses. (For those who may still be unaware, please refer to the links for ISVP and Bonus Rewards.)
  6. However, many of highly awarded reports, including the top rewards, were submitted before the launch of Bonus Reward and ISVP, resulting in additional bonuses not being awarded. Additionally, after launching these new programs, although we have received various reports targeting ISVP, no reports have yet met the ISVP criteria to claim the reward.
  7. We are prepared to offer higher rewards for critical scenarios with high-impact vulnerabilities. We kindly ask for more attention and participation and hope to have the opportunity to offer ISVP rewards before the end of this year.
We recognize that,
  1. we still have progress to make and are committed to refining our approach through continuous learning and improvement.
  2. Last month, with the release of the Hall of Fame, we received feedback from friends who provided significant help to our program last year. We acknowledged the need for improvements in various areas, so after having many discussions, we are conducting internal reviews.
  3. Here are a few examples:
    • There was feedback regarding the unclear explanation and operational approach for ISVP and Good Report Bonus.
      • We are preparing updates that include clearer and more intuitive guidance.
    • Suggestions were provided about improving the transparency of duplicate report.
      • For reports identified as 'Duplicated' (if the vulnerability has already been reported or is preparing patch after being found internally), we are preparing to provide additional explanations or (when possible) references during the process.
    • There was a request to share the patch schedule in advance.
      • We are reviewing options to share confirmed patch schedules with reporters ahead of the public Security Update disclosure.
  4. Through your diverse advices, we are filling the gaps by reflecting on aspects we had not considered before, and we believe that through close collaboration, we can create a safer product ecosystem.
  5. We always welcome suggestions for improvement.
We are planning to,
  1. encourage reports on high-impact vulnerabilities.
  2. Gradually increasing high-impact vulnerabilities
  3. In 2024, the proportion of high-impact vulnerabilities, including remote code execution vulnerabilities, has been gradually increasing. By increasing the number of high-impact reports, we could proactively prevent serious impact on products, and offer more rewards to our friends. So, we also aim to strengthen rewards for higher-severity vulnerabilities.
  4. We continuously explore ways to encourage more research including activating the ISVP and enhancing rewards for high-impact reports. We will share additional updates on this matter as well.
  1. Based on diverse feedback and internal discussions, we will operate the program in a way that fosters greater trust and comfort for our friends to share their findings. If you have any good suggestions and feedback to help us fill in the gaps, please feel free to share them with us via mobile.security@samsung.com or through our website.
  2. Once again, I would like to express my heart felt gratitude to my friends, our valuable security researchers. And I sincerely appreciate for the efforts of my team, Samsung Project Infinity at Samsung Mobile Security.
  3. 감사합니다!
Recently Post
  • Announcement
    Annual Report in 2024

    04 Jun 2025

  • Announcement
    Update to Our PGP Key for Email Reports and Communications

    04 Jun 2025

  • Announcement
    Annual Report in 2023 and New Announcements

    06 Aug 2024

  • Announcement
    Important Scenario Vulnerability Program

    06 Aug 2024

  • Announcement
    Bonus Rewards

    06 Aug 2024