logo

Samsung boosts bug bounty to a cool million for cracks of the Knox Vault subsystem

ID: 5c9e0bc7-1d4d-5412-96cb-f81949ae9531

STIX ID: report--5c9e0bc7-1d4d-5412-96cb-f81949ae9531

Feed Name: The Register (Security)

Date Published: 2024-08-08

Date Updated: 2026-04-26

Author: Iain Thomson

...
...

Samsung has raised its bug bounty stakes, offering up to $1M for a zero-click compromise of Knox Vault on Galaxy S/Z devices, with additional rewards including $400k/$200k for remote/local TEEGRIS OS compromises, $300k/$150k for remote/local REE attacks (varying by privilege gain and code execution), up to $400k for extracting user data before first unlock, $100k for defeating Auto Blocker with persistence, and $100k/$50k (third-party store) or $60k/$30k (Galaxy Store) for remote/local app installs; despite high caps, historical payouts have been modest (under $5M total to date, $827,925 in 2023 with a top award of $57,190), while Microsoft paid $16.6M in the last year, highlighting differing bounty ecosystems and the role of researcher incentives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.