close

Samsung Mobile Security
Cookie Policy

Updated on Jan 17, 2022

This Cookie Policy describes the different types of cookies that may be used in connection with Samsung Mobile Security website which is owned and controlled by Samsung Electronics Co., Ltd (“Samsung Electronics”). This Cookie Policy also describes how you can manage cookies.

It’s important that you check back often for updates to the Policy as we may change it from time to time to reflect changes to our use of cookies. Please check the date at the top of this page to see when this Policy was last revised. Any changes to this Policy will become effective when we make the revised Policy available on our website.

Samsung Electronics has offices across Europe, so we can ensure that your request or query will be handled by the data protection team based in your region. If you have any questions, the easiest way to contact us is through our Privacy Support Page at https://www.samsung.com/request-desk.

You can also contact us at:

European Data Protection Officer
Samsung Electronics (UK) Limited
Samsung House, 2000 Hillswood Drive, Chertsey, Surrey KT16 0RS

Cookies

Cookies are small files that store information on your computer, TV, mobile phone, or other device. They enable the entity that put the cookie on your device to recognize you across different websites, services, devices, and/or browsing sessions.

We use the following types of cookies on this website:

Essential Cookies: enable you to receive the services you request via our website. Without these cookies, services that you have asked for cannot be provided. For example, these enable to identify users and provide proper service for each user. These cookies are automatically enabled and cannot be turned off because they are essential to enable you to browse our website. Without these cookies this Samsung Mobile Security website could not be provided.

Cookie Domain Purpose
JSESSIONID security.samsungmobile.com to keep login session
lastActivityTime security.samsungmobile.com to save the user's last activity time to automatically logout after 30 minutes of inactivity

Managing Cookies and Other Technologies

You can also update your browser settings at any time, if you want to remove or block cookies from your device (consult your browser's "help" menu to learn how to remove or block cookies). Samsung Electronics is not responsible for your browser settings. You can find good and simple instructions on how to manage cookies on the different types of web browsers at http://www.allaboutcookies.org.

Go straight to the menu Go straight to the text

Security Post

Announcement

Program Policy Update: Report Quality Requirements and Submission Limits

Jasper Sangjoon Park, Head of Samsung Project Infinity at Samsung Mobile Security
  1. Thank you for your continued contributions to the security of Samsung Mobile products and services. Your reports help us identify and remediate high-impact vulnerabilities before they can affect our users, and we remain committed to rewarding high-quality research fairly and promptly.
  2. As automated, unverified AI-generated reports have become widespread, the overall volume of reports to our program has increased significantly. To keep report analysis and remediation timely, and to ensure that solid, high-quality reports are reviewed and rewarded without delay, we are updating the following program policies, effective September 9, 2026 (KST). Reports submitted before the effective date will be handled under the previous policy.
  3. The primary purpose of this change is to clarify our expectations for report quality, ensuring that we can focus our resources on the high-impact vulnerabilities. We continue to welcome vulnerability research, and this update does not narrow the scope of the program. Eligible reports will continue to be rewarded fairly.
A Working Proof-of-Concept Is Required
  1. Every submission must include a working Proof-of-Concept (PoC) that demonstrates a concrete security impact.
    • Reports based only on static code review, without a working PoC, will be determined as Not Eligible.
    • A report that only demonstrates a crash is not eligible for a reward and may be forwarded to the development team for a stability review. However, if the report provides verifiable evidence that the crash leads to a practical security impact — such as control of the program counter or execution flow, controlled memory corruption, a denial of service that qualifies under the Severity Classification, or another clearly demonstrated security impact recognized under the program's reward criteria — it will be assessed as eligible.
    • A crash must be reachable in a practical attack path. Crashes produced by artificially bypassing the product's legitimate attack surface — for example, directly loading a native library via dlopen and calling its internal APIs with malformed input, without going through the input validation performed by the calling layers in the actual product — are not considered a valid security impact. Such reports will be determined as Not Eligible unless concrete evidence is provided that the same input can reach the affected code through a legitimate attack path.
    • Severity and reward amounts are determined based on the impact demonstrated by the provided PoC. Claims or assumptions of a higher potential impact – for example, asserting that remote code execution is achievable – are generally not considered valid impact unless supported by a working demonstration.
The Standard Submission Template Is Mandatory
  1. To speed up validation and reproduction, every submission must include a completed template file describing the vulnerability, test environment, and reproduction steps.
  2. ※ For details on the submission template, please refer to the Standard Submission Template Guide.
  3. Submission of the template is a mandatory requirement for all reports. Because a completed template helps us validate and reproduce a report more quickly, submitting a complete template can lead to faster patching and rewards. Unlike the PoC requirement, a missing or incomplete template does not automatically make a valid report Not Eligible.
    • The template consists of required fields and recommended fields. Templates are assessed as follows:
      • Fully complete: All required and recommended fields are completed accurately.
      • Partially complete: All required fields are completed accurately, but some recommended fields are missing. Leaving recommended fields blank does not by itself make a template incomplete.
      • Incomplete: One or more required fields are not completed, or no template is submitted.
    • The Good Report Bonus is paid on a tiered basis according to the completeness of the template: A fully complete template receives the full Good Report Bonus, and a partially complete template receives a partial Good Report Bonus. Reports with an incomplete template are not eligible for the Good Report Bonus.
    • An incomplete or missing template does not by itself result in a report being determined as Not Eligible – if the practical security impact is sufficiently demonstrated by PoC, remediation and reward assessment will still proceed. However, in such cases the base reward is substantially reduced.
  4. ※ Details on how these requirements relate to the Good Report Bonus and ISVP rewards are covered in a separate Reward Policy Update.
Focusing Review Capacity on Validated Findings
  1. We welcome the responsible use of AI-assisted research tools. Regardless of the tools used, researchers remain responsible for independently validating each submitted finding and confirming its reproducibility and practical security impact.
    • Reports that share the same root cause and impact as an existing report are closed under our existing duplicate-report policy.
    • Reports that repeatedly lack validation, reproduction steps, or evidence of security impact may be deprioritized in our review queue, and submissions may be restricted.

Monthly Submission Limits


  1. To ensure timely review and remediation for all researchers, monthly submission quotas are dynamically assigned based on each researcher's submission history and report quality.
    • Monthly Quotas: Quotas are refreshed on a monthly basis.
    • Slot Availability: As active submissions are resolved, additional submission capacity becomes available.
    • Individual Basis: Quotas apply per individual researcher rather than per account. Bypassing limits through multiple accounts is not permitted and may result in quota restrictions.
    • Exemptions: Researchers with a consistent record of high-quality, high-impact, and well-verified reports may receive higher quotas or exemptions.
References
  1. Please check the following notices on our official website.
  1. With deep respect and gratitude for the researchers' support, our rewards program will continue to operate so that high-impact research is rewarded fairly and quickly. This change is intended to allow us to spend our time where it matters most: on your most important findings.
  2. For any questions, please contact us, Samsung Mobile Security (mobile.security@samsung.com).
Recently Post
  • Announcement
    Program Policy Update: Report Quality Requirements and Submission Limits

    08 Sep 2026

  • Announcement
    Reward Policy Update

    08 Sep 2026

  • Announcement
    Standard Submission Template Guide

    08 Sep 2026

  • Announcement
    Annual Report in 2025

    16 Mar 2026

  • Announcement
    ISVP Milestone & Update

    16 Mar 2026