Arm is committed to security and welcomes feedback from researchers and the security community to improve its products and services.
The Arm Bug Bounty Program represents a partnership between Arm and the research community. At Arm, we value collaboration with security researchers as a critical step toward enhancing the security of our products. We encourage researchers to work with us to identify, mitigate, and responsibly disclose potential security vulnerabilities. We look forward to collaborating with you!
This program currently welcomes reports of vulnerabilities in certain versions of:
- Firmware: Mali Command Stream Frontend (CSF) Firmware 'CSFFW'
- Software: Mali GPU Kernel Driver (Kbase)
By submitting your report, you agree to the terms of the Arm Bug Bounty Program. Arm reserves the right to alter the terms and conditions of this program at any time and its sole discretion.