close

Samsung Mobile Security
Cookie Policy

Updated on Jan 17, 2022

This Cookie Policy describes the different types of cookies that may be used in connection with Samsung Mobile Security website which is owned and controlled by Samsung Electronics Co., Ltd (“Samsung Electronics”). This Cookie Policy also describes how you can manage cookies.

It’s important that you check back often for updates to the Policy as we may change it from time to time to reflect changes to our use of cookies. Please check the date at the top of this page to see when this Policy was last revised. Any changes to this Policy will become effective when we make the revised Policy available on our website.

Samsung Electronics has offices across Europe, so we can ensure that your request or query will be handled by the data protection team based in your region. If you have any questions, the easiest way to contact us is through our Privacy Support Page at https://www.samsung.com/request-desk.

You can also contact us at:

European Data Protection Officer
Samsung Electronics (UK) Limited
Samsung House, 2000 Hillswood Drive, Chertsey, Surrey KT16 0RS

Cookies

Cookies are small files that store information on your computer, TV, mobile phone, or other device. They enable the entity that put the cookie on your device to recognize you across different websites, services, devices, and/or browsing sessions.

We use the following types of cookies on this website:

Essential Cookies: enable you to receive the services you request via our website. Without these cookies, services that you have asked for cannot be provided. For example, these enable to identify users and provide proper service for each user. These cookies are automatically enabled and cannot be turned off because they are essential to enable you to browse our website. Without these cookies this Samsung Mobile Security website could not be provided.

Cookie Domain Purpose
JSESSIONID security.samsungmobile.com to keep login session
lastActivityTime security.samsungmobile.com to save the user's last activity time to automatically logout after 30 minutes of inactivity

Managing Cookies and Other Technologies

You can also update your browser settings at any time, if you want to remove or block cookies from your device (consult your browser's "help" menu to learn how to remove or block cookies). Samsung Electronics is not responsible for your browser settings. You can find good and simple instructions on how to manage cookies on the different types of web browsers at http://www.allaboutcookies.org.

Go straight to the menu Go straight to the text

Security Post

Announcement

Reward Policy Update

Samsung Mobile Security
  1. We continuously review our reward policies to ensure that important vulnerabilities discovered through researchers' valuable work are rewarded fairly and transparently. In line with the Program Policy Update announced together with this notice, we are sharing the reward policy update below.
PoC Eligibility Requirement
  1. Starting September 9, 2026 (KST), a working PoC is a mandatory requirement for every report, and reports without a working PoC are excluded from rewards under the Samsung Mobile Security Rewards Program. For example, a report based only on static code review, without a working PoC, will be determined as Not Eligible. In addition, a report whose PoC only demonstrates that a crash occurs is not eligible for a reward and may be forwarded to the development team for a stability review. However, if evidence is provided that the crash leads to one of the following practical security impacts, the report may be assessed for a reward:
    • Control of the program counter or execution flow
    • Controlled memory corruption
    • A denial of service that qualifies under the Severity Classification
    • Another clearly demonstrated security impact recognized under the Severity Classification
  2. Furthermore, the demonstrated impact must be reachable through a practical attack path. Crashes produced by artificially bypassing the product's legitimate attack surface — such as directly invoking internal library APIs via dlopen with malformed input — are not considered a valid security impact.
Template Requirement
  1. Mandatory Standard Submission Template
  2. Starting September 9, 2026 (KST), every report must include the standard submission template with the required fields completed. The template captures the essential information about the report, including the reproduction steps, and submission of the template is a mandatory requirement for all reports.
  3. The template consists of required fields and recommended fields, and templates are assessed as follows:
    • Fully complete: All required and recommended fields are completed accurately.
    • Partially complete: All required fields are completed accurately, but some recommended fields are missing. Leaving recommended fields blank does not by itself make a template incomplete.
    • Incomplete: One or more required fields are not completed, or no template is submitted.
  4. Unlike the PoC eligibility requirement, an incomplete or missing template does not by itself result in a report being determined as Not Eligible – if the practical security impact is sufficiently demonstrated, remediation and reward assessment will still proceed. In such cases, the base reward is substantially reduced, and the report is not eligible for the Good Report Bonus.
  5. ※ For details on template submission, please refer to the Standard Submission Template Guide.
Good Report Bonus
  1. We continue to pay an additional reward for well-written reports through the Good Report Bonus. The Good Report Bonus applies only to vulnerabilities in Android mobile devices (smartphones and tablets). Vulnerabilities in other products, such as wearables, and server-side, web service, or backend vulnerabilities are not eligible for the Good Report Bonus and are assessed for a base reward under the existing policy.
  2. For vulnerabilities with a final severity of High or Critical, a fully complete template receives the full Good Report Bonus, providing a total reward of up to twice the base reward, and a partially complete template receives a partial Good Report Bonus. For vulnerabilities rated Moderate, a partial Good Report Bonus is paid only when the template is fully complete. Reports rated Low or reports with an incomplete template are not eligible for the Good Report Bonus and are assessed for a base reward under the existing criteria.

Requirements for the Full Good Report Bonus


  1. A report may receive the full Good Report Bonus when it satisfies all of the following:
    • A valid and reward-eligible Android mobile device (smartphone or tablet) vulnerability
    • A final severity rated High or Critical
    • A working PoC that demonstrates a practical security impact
    • A fully complete template, in which both the required and recommended fields are completed accurately for the reported vulnerability

Recommended Items


  1. Completing the required fields alone is sufficient to submit a report. However, to receive the full Good Report Bonus, the recommended items must also be accurately included in the template and submitted materials. This information helps us analyze the vulnerability and develop a patch quickly.
ISVP Submissions
  1. ISVP is a special reward program with the strictest requirements, and its reward is paid only to reports that satisfy all of its requirements. A report that fails to satisfy any one of these requirements — including a working PoC, Exploit and fully complete template — is not eligible for the ISVP reward. In that case, the report itself remains valid, and its base reward and Good Report Bonus are assessed under the same criteria as any other report. The existing ISVP reward structure and reward amounts remain unchanged.
  2. If you are claiming an ISVP reward, the ISVP section of the template must be completed. It records the Important Scenario and target being claimed, the attack vector, whether the exploit executes without privileges, whether it was verified on the latest security update of the latest flagship devices, and the buildable exploit provided.
Report Handling Summary
  1. Report typeTreatment
    High or Critical Android mobile device vulnerability with a working PoC and a fully complete templateBase reward assessment; full Good Report Bonus
    High or Critical Android mobile device vulnerability with a working PoC and a partially complete templateBase reward assessment; partial Good Report Bonus
    Android mobile device vulnerability rated Moderate with a working PoC and a fully complete templateBase reward assessment; partial Good Report Bonus (no Good Report Bonus for partially complete or incomplete template)
    Android mobile device vulnerability rated LowBase reward assessment; no Good Report Bonus
    Server-side, backend or other product (e.g., wearable) vulnerabilityBase reward assessment; no Good Report Bonus
    Working PoC and demonstrated security impact, but template missing or incompleteBase reward substantially reduced; no Good Report Bonus
    Crash only, without a demonstrated practical security impactNot Eligible
    Static code review only, without a working PoCNot Eligible
    Fully satisfied ISVP requirements (demonstrating the described scenario + Exploit + fully complete template)ISVP reward
    Any one of the ISVP requirements (demonstrating the described scenario + Exploit + fully complete template) not satisfiedNo ISVP reward; base reward and Good Report Bonus assessed under the standard criteria

  1. This reward policy update supplements the existing Good Report Bonus policy; where the two conflict, this update takes precedence.
  2. We appreciate your continued interest and participation in the Samsung Mobile Security Rewards Program.
Recently Post
  • Announcement
    Program Policy Update: Report Quality Requirements and Submission Limits

    08 Sep 2026

  • Announcement
    Reward Policy Update

    08 Sep 2026

  • Announcement
    Standard Submission Template Guide

    08 Sep 2026

  • Announcement
    Annual Report in 2025

    16 Mar 2026

  • Announcement
    ISVP Milestone & Update

    16 Mar 2026