Samsung has significantly increased its bug bounty program as part of its ongoing efforts to enhance mobile security.
The tech giant is now offering rewards of up to $1 million for researchers who can demonstrate critical vulnerabilities in its mobile devices, particularly those related to arbitrary code execution on highly privileged targets.
This new initiative, part of Samsung’s Important Scenario Vulnerability Program (ISVP), focuses on vulnerabilities that could significantly impact their products. The program specifically targets the following critical scenarios:
Are you from SOC and DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Free Access
The highest reward of $1 million is reserved for remote arbitrary code execution vulnerabilities targeting Knox Vault, Samsung’s secure environment for storing sensitive data. Other notable rewards include:
To qualify for these top-tier rewards, researchers must meet several criteria:
Samsung’s increased bounties reflect mobile security’s growing importance in an era of increasingly sophisticated cyber threats. Samsung encourages security researchers to find and report critical vulnerabilities, aiming to prevent potential attacks and protect users’ data.
This move aligns with Samsung’s long-standing commitment to mobile security. The company has been running its Mobile Security Rewards Program since 2016, continuously updating it to cover new devices and services.
The program now encompasses 38 Samsung mobile devices that receive monthly and quarterly security updates and various Samsung Mobile Services like Bixby, Samsung Account, Samsung Pay, and Samsung Pass.
By significantly increasing the potential rewards, Samsung is not only attracting more security researchers to detect vulnerabilities in its products but also showing its commitment to maintaining high standards of security for mobile devices in an increasingly complex digital world.
How to Build a Security Framework With Limited Resources IT Security Team (PDF) - Free Guide
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…