Moneycontrol PRO
HomeTechnologySamsung is offering up to million dollars for ‘hacking’ its software, devices

Samsung is offering up to million dollars for ‘hacking’ its software, devices

According to a blog post by Samsung, security researchers – as well as others – can earn rewards if they can find any vulnerabilities.

August 08, 2024 / 16:22 IST
Samsung

Samsung

Like most big tech companies, Samsung also has a bug bounty program. Samsung offers significant rewards to those who can find security flaws and vulnerabilities in its software as a part of its Mobile Security Program. The company has now increased the rewards of the bug bounty program to a  million dollars.

According to a blog post by Samsung, security researchers – as well as others – can earn rewards if they can find any vulnerabilities related to Arbitrary Code Execution on privileged targets. This includes things like unlocking devices, data extraction, executing arbitrary application installation or bypass the device's security.

Samsung has explained  that users can earn rewards by finding different types of security flaws in their system. The top $1 million  reward can be earned by exploiting Knox Vault and executing a remote code in the Samsung's hardware security system.

Samsung Mobile Security rewards

Product/ServiceLocal ACE CostRemote ACE Cost
Knox Vault$300,000$1,000,000
TEEGRIS OS$200,000$400,000
Rich OS$150,000$300,000

Apart from these, a subsequent device unlock after the first unlock will get them $200,000. However, if anyone unlocks it without the phone being unlocked earlier, the reward gets bumped up to $400,000. If you can manage to install an application from the Galaxy Store remotely then Samsung will give you $60,000 and $30,000 for local install. The reward for installing an application from other sources remotely and locally is set at $100,000 and $50,000.

Eligibility criteria

According to Samsung's blog post, the report should showcase a successful attack targeting important scenarios.

To qualify for the Good Report Bonus, the submission must include an exploit that successfully targets one or more of the defined Important Scenarios.

The exploit must be effective on the latest security updates of the latest flagship Galaxy S and Z series devices. It should be executable without requiring elevated privileges. When submitting through the rewards program, include the prefix [ISVP] in your report title to join the program.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Shaurya Shubham
first published: Aug 8, 2024 03:25 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347