Electronic Arts · Vulnerability Disclosure

Electronic Arts Vulnerability Disclosure

Vulnerability disclosure

Electronic Arts runs a coordinated vulnerability disclosure program on Hackerone.

GamingVideo GamesEntertainmentConsumerPlayer ServicesFortune 1000
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

electronic-arts-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-06'
method: searched
probe: true
source: https://www.ea.com/security/disclosure
evidence:
- source: https://www.ea.com/security
  kind: disclosure page
  status: 200
  keywords:
  - vulnerability
  - security issue
- source: https://www.ea.com/security/disclosure
  kind: vulnerability disclosure policy
  status: 200
- source: https://www.ea.com/security/advisories
  kind: security advisories
  status: 200
- source: https://www.ea.com/security/hall-of-fame
  kind: researcher recognition
  status: 200
program:
  name: EA Vulnerability Disclosure
  policy_url: https://www.ea.com/security/disclosure
  submission_url: https://forms.ea.com/app/form?id=222
  submission_method: web form
  contact_email: null
  advisories_url: https://www.ea.com/security/advisories
  hall_of_fame_url: https://www.ea.com/security/hall-of-fame
  bug_bounty: false
  bounty_platform: null
  rewards: >-
    None. EA's submission terms state a report "grants EA all licenses needed to enable
    EA's use of the report for any purpose without notice, attribution or compensation to
    you." Recognition is via the Hall of Fame page rather than payment.
  in_scope_examples:
  - cross-site scripting
  - SQL injection
  - publicly exposed credentials
  - subdomain takeover
  - system misconfigurations with demonstrated security impact
  safe_harbor: >-
    No explicit safe-harbor clause is published. EA asks researchers to keep the issue
    confidential until it has had adequate time to investigate and address it, and cites
    CERT's Coordinated Vulnerability Disclosure guidance.
  response_commitment: >-
    None stated; EA's own disclaimer says "We may not respond to every report."
  security_txt: false
gaps:
- >-
  The programme is real and easy to find from ea.com, but it is not advertised at the
  RFC 9116 path: /.well-known/security.txt returns 404 on ea.com, www.ea.com, help.ea.com,
  accounts.ea.com, signin.ea.com and gateway.ea.com. A single security.txt naming
  https://www.ea.com/security/disclosure would make the whole programme machine-discoverable.
- >-
  No third-party bounty platform is operated: hackerone.com/ea and
  hackerone.com/electronic-arts both return 404, and bugcrowd.com/ea resolves to the generic
  Bugcrowd portal rather than an EA programme.
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/electronic-arts-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.