Trusted Firmware Logo

A New Bug Bounty Program for Trusted Firmware!

logo
Trusted Firmware| Monday, December 8, 2025|3 min read

A new Bug Bounty Program for Trusted Firmware!

The Trusted Firmware project is pleased to share that several of its projects have been included in a new Trusted Firmware Bug Bounty Program, which is being provided and operated by Arm.

Trusted Firmware projects form essential building blocks for secure boot, trusted execution, and cryptographic operations across a wide range of Arm-based platforms. Arm’s decision to include them in the Bug Bounty program for Trusted Firmware demonstrates the importance of proactive, community-driven security across the ecosystem and the significance of these projects as foundational to the security of the Arm ecosystem.

The following projects are included in the program:

As open-source reference implementations and security libraries, these projects are widely integrated by silicon vendors, OEMs and developers. Also because these components sit at the root of trust for many products, improving their resilience benefits the entire ecosystem.

Security researchers who identify issues in the in-scope projects can report them to the Bug Bounty Program for Trusted Firmware, which is hosted on the Intigriti platform. Reports will be jointly assessed by Arm’s Product Security Incident Response Team (PSIRT) and the Trusted Firmware security team, with qualifying issues being eligible for financial rewards based on severity and impact.

More information

The Trusted Firmware project encourages security researchers, contributors and integrators to explore a broad range of security areas, including secure boot flows, isolation boundaries, privilege transitions, cryptographic implementations and protocol handling.

Participation guidelines, scope details, reward information and the submission form are available here.

The Trusted Firmware project welcomes the continued collaboration of researchers and partners, as we work together to enhance the security of the ecosystem.



About the Linaro Community Projects Division

The Trusted Firmware project is hosted by Linaro Community Projects Division - the division of Linaro managing open source community projects with open governance. Linaro empowers rapid product deployment within the dynamic Arm ecosystem.

Recent Posts

post image
MCUboot v2.3.0 Release!

Friday, December 19, 2025

MCUboot v2.3.0 Release

post image
A New Bug Bounty Program for Trusted Firmware!

Monday, December 8, 2025

Trusted Firmware launches a new Bug Bounty Program!

post image
Trusted Firmware-A v2.14 released!

Wednesday, November 26, 2025

Introduction Trusted Firmware-A (TF-A) 2.14 has been officially released, delivering a host of enhancements focused on security, platform support, and maintainability. This release introduces key updates including support for Arm Architecture features, expanded RMM functionality, and improved integration with third-party firmware components. TF-A 2.14 also strengthens its...

post image
How do AI-assisted contributions fit into open source?

Friday, November 14, 2025

Trusted Firmware has just released its "Guidance on AI-assisted contributions."

post image
Introducing Rusted Firmware-A (RF-A) - A Rust-Based reimagination of Trusted Firmware-A

Tuesday, August 19, 2025

Why Rusted Firmware-A?