close

Samsung Mobile Security
Cookie Policy

Updated on Jan 17, 2022

This Cookie Policy describes the different types of cookies that may be used in connection with Samsung Mobile Security website which is owned and controlled by Samsung Electronics Co., Ltd (“Samsung Electronics”). This Cookie Policy also describes how you can manage cookies.

It’s important that you check back often for updates to the Policy as we may change it from time to time to reflect changes to our use of cookies. Please check the date at the top of this page to see when this Policy was last revised. Any changes to this Policy will become effective when we make the revised Policy available on our website.

Samsung Electronics has offices across Europe, so we can ensure that your request or query will be handled by the data protection team based in your region. If you have any questions, the easiest way to contact us is through our Privacy Support Page at https://www.samsung.com/request-desk.

You can also contact us at:

European Data Protection Officer
Samsung Electronics (UK) Limited
Samsung House, 2000 Hillswood Drive, Chertsey, Surrey KT16 0RS

Cookies

Cookies are small files that store information on your computer, TV, mobile phone, or other device. They enable the entity that put the cookie on your device to recognize you across different websites, services, devices, and/or browsing sessions.

We use the following types of cookies on this website:

Essential Cookies: enable you to receive the services you request via our website. Without these cookies, services that you have asked for cannot be provided. For example, these enable to identify users and provide proper service for each user. These cookies are automatically enabled and cannot be turned off because they are essential to enable you to browse our website. Without these cookies this Samsung Mobile Security website could not be provided.

Cookie Domain Purpose
JSESSIONID security.samsungmobile.com to keep login session
lastActivityTime security.samsungmobile.com to save the user's last activity time to automatically logout after 30 minutes of inactivity

Managing Cookies and Other Technologies

You can also update your browser settings at any time, if you want to remove or block cookies from your device (consult your browser's "help" menu to learn how to remove or block cookies). Samsung Electronics is not responsible for your browser settings. You can find good and simple instructions on how to manage cookies on the different types of web browsers at http://www.allaboutcookies.org.

Go straight to the menu Go straight to the text

Security Reporting

If you have identified a potential security vulnerability in any Samsung Mobile product or software,
please report it here

Please carefully read the reporting guidelines below and Samsung’s security risk classification criteria prior to reporting.

We encourage the reporting party to place the users’ interest first and follow the philosophy of Responsible Disclosure, which involves privately notifying us of any security vulnerabilities before disclosing them fully to allow us to resolve the vulnerabilities and minimize overall risk to users.
Reporting Guidelines

Submitted reproduction commands and scripts may be executed in an isolated sandbox for validation purposes. They must contain only the actions needed to reproduce the issue; destructive or out-of-scope commands are not executed and may cause the report to be rejected.

Report via ticketing system

Create Report Samsung Account required JOIN
Note: Reports not submitted through "ticketing system", but sent directly to us via email are not eligible for a reward.
  • When reporting the security vulnerability you have identified through the ticketing system, you will be able to receive prompt response and track the status of the ticket you reported in real time while directly communicating with a dedicated security analyst. Samsung Account is required to submit a ticket and you need to create a user account if you do not have an existing account.
  • If you would like to submit a security vulnerability report directly to us via email, please send your report to mobile.security@samsung.com including the detailed technical information and encrypted with Samsung Mobile Security’s public PGP key (Fingerprint: B146 7CFB F71D BB18 84E2 6FAC 9151 3E50 B0FB FD2F). We will immediately send the confirmation that we received your report, and share an update of the progress by email.
  • For quick and accurate analysis, we ask you to provide detailed information and we may ask you to provide additional information if necessary.
Required Information
  1. All reports must include the following items in order to be determined eligible.
    • Version information of the affected product, including the build number (Settings > About device > Software information > Build number)
    • Description of the vulnerability that properly explains the practical security impact
    • Detailed steps to reproduce the report (including video, image, or other means where needed)
    • Working Proof-of-Concept (PoC) that demonstrates a concrete security impact
    • Disclosure plans, if any
  2. In addition, submission of a completed submission_template_v10.yaml is mandatory for all reports. Unlike the PoC requirement, a missing or incomplete template does not by itself make an otherwise valid vulnerability report Not Eligible; however, when the required fields are not completed, the base reward is substantially reduced and the report is not eligible for the Good Report Bonus.
  3. Please download the template from the Standard Submission Template Guide and attach it, zipped together with your PoC artifacts, to your report.
  4. We continue to offer extra rewards for well-written reports through the Good Report Bonus. It applies only to Android mobile device-side (smartphone/tablet) vulnerabilities; wearable, PC, server-side, web service, and backend vulnerabilities remain eligible for a base reward but not for the Good Report Bonus. For High or Critical findings a fully complete template earns the full bonus and a partially complete template earns a partial bonus; for Moderate findings a partial bonus is paid only when the template is fully complete. See the Reward Policy Update.
Responsible Disclosure Policy
  • At Samsung, we take security and privacy issues very seriously, and we value the security research community with our commitment to address potential security vulnerabilities as quickly as possible. The responsible disclosure of security vulnerabilities helps us ensure the security and privacy of our end-consumers.
  • We ask our security research community to:
    • Make every effort to avoid privacy violations, degradation of user experience, disruption to internal or external servers, and destruction of data or physical assets during security testing.
    • Use reporting guidelines stated above to report details of potential vulnerabilities as complete as possible.
    • Keep information about the potential vulnerability discovered confidential between yourself and Samsung until we have remedy in place.
    • Restrain from using any exploits or vulnerabilities for commercial or business purpose.
    • Independently validate and reproduce each submitted finding, and confirm its practical security impact, regardless of the tools used. We welcome the responsible use of AI-assisted research tools, but the responsibility for validation remains with the reporter.
    • Use test accounts that you own when producing evidence. Do not submit other people's personal data; where it is unavoidable as evidence, mask it before submission.
  • In return, we commit to:
    • Work with you to understand and resolve the potential vulnerability quickly.
    • Make our best effort to resolve security vulnerabilities, and release patches to end-consumers within 90 days.
    • Reward you, if you choose to participate in our Samsung Mobile Security Rewards Program, and recognize your contribution through our Acknowledgements for eligible reports.

Investigating and reporting bugs

Note that two reporting channels linked above are intended for reporting security vulnerabilities of Samsung Mobile products and its related services. If the identified potential vulnerability applies to other Samsung products or services, please visit here to report to the corresponding business unit’s reporting channel.