Wyze · Vulnerability Disclosure

Wyze Vulnerability Disclosure

Vulnerability disclosure

Wyze runs a coordinated vulnerability disclosure program on Bugcrowd. A dedicated security contact is published.

CompanySmart HomeInternet of ThingsHome SecurityCameraConsumer ElectronicsHome AutomationVideoSensorsCommerce
Program: Bugcrowd

Disclosure Policy

Policy
Policy
Policy

Security Contact

Contact
security@wyze.com

Source

Vulnerability Disclosure

wyze-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-02'
method: searched
probe: true
source: >-
  https://global.wyze.com/pages/security-report (full published policy text),
  https://www.wyze.com/pages/wyzes-vulnerability-disclosure,
  https://www.wyze.com/pages/security-report and https://bugcrowd.com/engagements/wyze
policy:
- https://www.wyze.com/pages/wyzes-vulnerability-disclosure
- https://global.wyze.com/pages/security-report
- https://bugcrowd.com/engagements/wyze
contact:
- security@wyze.com
security_txt: none
last_updated: 'January 2026'
bug_bounty:
  platform: Bugcrowd
  url: https://bugcrowd.com/engagements/wyze
  name: Wyze Bug Bounty
  out_of_scope_intake: wyzevpd@submit.bugcrowd.com
  rating_taxonomy: Bugcrowd Vulnerability Rating Taxonomy (VRT)
  scope_note: >-
    Wyze states it welcomes security researchers to help identify vulnerabilities in its
    web app and API.
process:
  steps:
  - id: reporting
    description: >-
      The Wyze Cybersecurity team becomes aware of a potential vulnerability; the reporter
      receives an acknowledgement and updates throughout handling.
  - id: evaluation
    description: >-
      The team confirms the vulnerability, assesses risk and impact, and assigns a
      processing priority.
  - id: solution
    description: >-
      A fix is developed with the product team; where a vulnerability is actively
      exploited a temporary containment may ship ahead of the full solution.
  - id: communication
    description: >-
      A security advisory is published for severe issues; less severe issues are
      communicated through other methods.
  slas:
    acknowledgement: within 48 hours (business days)
    status_updates: at least once every 7 days while under investigation or remediation
    resolution_target: approximately 3-4 weeks for confirmed vulnerabilities
  submission_guidance:
  - clear description of the issue
  - the affected product or service
  - steps to reproduce, if known
  - relevant screenshots, logs, or proof-of-concept information
  responsible_disclosure: >-
    Wyze asks that issues not be publicly disclosed until it has had a reasonable
    opportunity to investigate and address them, and commits to working in good faith
    with reporters.
  safe_harbor_note: >-
    Wyze states that reporting a security vulnerability will not affect product warranty
    or access to customer support. No formal legal safe-harbour clause is published on
    the disclosure page itself.
suspicious_activity_intake:
  url: https://www.wyze.com/pages/security-report
  contact: security@wyze.com
  requested_details:
  - detailed description of the issue
  - products and versions affected
  - device MAC address (ID)
  - account email address
  - time of the issue
  - submitted Log ID from the mobile app
evidence:
- source: https://global.wyze.com/pages/security-report
  kind: disclosure-policy
  http_status: 200
  keywords: [responsible disclosure, security@wyze.com, vulnerability, acknowledgement]
- source: https://www.wyze.com/pages/wyzes-vulnerability-disclosure
  kind: disclosure-page
  http_status: 200
  note: >-
    Shopify page rendered client-side with template suffix "bugcrowd" - it embeds the
    Bugcrowd program rather than serving static policy text.
- source: https://bugcrowd.com/engagements/wyze
  kind: bug-bounty
  http_status: 200
- source: https://www.wyze.com/pages/security-trust
  kind: security-hub
  http_status: 200
x-evidence:
  fetched: '2026-08-02'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/wyze-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.