Sky Bug Bounty Program Vulnerability Report

Thank you for contacting us with information about vulnerabilities.
The information will be put in use for further improving the quality of our products, services, and websites.

Before contacting us about the vulnerability

Before contacting us with information about vulnerabilities, please read the following carefully.

  • We manage Sky Bug Bounty Program that we will pay a reward for those who discover and report vulnerabilities. In case of not covered our products and services, you cannot acquire the reward.
  • Even if you do not participate in the program, you must comply with the Article 13 in "Sky Bug Bounty Program Terms and Conditions".
  • We ask for your cooperation in not telling other parties about any vulnerabilities. Your cooperation is greatly appreciated to prevent any damage to the users of our products, services and websites.
  • When reporting vulnerabilities, please refer to "Sky Bug Bounty Program Rulebook".
  • Please rest assured that Sky Co., Ltd. will bear the responsibility of taking appropriate measures, such as reporting the vulnerability to IPA. For details on how we will handle the vulnerability, please refer to our vulnerability handling policy.
  • By using this form, you agree to the privacy policy.

[Important] Notice Regarding Temporary Changes to the Sky Bug Bounty Program Acceptance Criteria

Due to the increase in AI-assisted submissions, we have received a large number of reports that lack sufficient validation, as well as duplicate or substantially similar reports. This has created a significant burden on our report intake and investigation processes. As this situation is impacting our ability to maintain our program operations and ensure the quality of our assessments, we regret to inform you that, for the purpose of reviewing and improving this program, reports that meet the following conditions will be temporarily excluded from both acceptance and reward eligibility:

  • Acceptance Restriction Based on CVSS Score
    Reports with a CVSS v3 score below 7.0.
    * If a report is found to have a CVSS v3 score below 7.0 after submission, it will be treated as ineligible for both acceptance and reward consideration, even if it has already been accepted for review.
  • Non-Reproducible Reports or Insufficient Attack Scenarios
    Reports for which a specific attack scenario (including exploitation methods and potential impact) cannot be verified.
    Reports that do not include a Proof of Concept (PoC) or clear reproduction steps.
  • Handling of Website (Web Application) Vulnerability Reports
    For website-related reports where calculating a CVSS score is difficult, the primary evaluation criterion will be whether a concrete attack scenario demonstrating objectively exploitable conditions is provided.
  • Reports Generated by AI or Automated Tools
    Reports consisting solely of static analysis results generated by AI or automated scanners.
    Reports that, in our judgment, rely on outputs from such tools without sufficient independent verification.

Please note that, even for reports that do not fall under any of the above categories, review and response times may be longer than usual due to the high volume of submissions currently being processed.

This is a temporary measure, and we will provide further updates once new operational rules and acceptance criteria have been established.

To Report Vulnerabilities

To participate in the bug bounty program and report

Please contact us from below. To participate in the bug bounty program and report, you must agree to the privacy policy and Sky Bug Bounty Program Terms and Conditions.

To report without participating in the program

Please contact us from below. To report without participating in the program, you must agree to the privacy policy.