Wyze · Vulnerability Disclosure

Wyze Vulnerability Disclosure

Vulnerability disclosure

Wyze runs a coordinated vulnerability disclosure program on Bugcrowd. A dedicated security contact is published.

CompanySmart HomeInternet of ThingsHome SecurityCamerasConsumer ElectronicsHome AutomationVideoSensorsCommerce
Program: Bugcrowd

Disclosure Policy

Policy
Policy
Policy

Security Contact

Contact
security@wyze.com

Source

Vulnerability Disclosure

wyze-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-02'
method: searched
probe: true
source: >-
  https://global.wyze.com/pages/security-report (full published policy text),
  https://www.wyze.com/pages/wyzes-vulnerability-disclosure,
  https://www.wyze.com/pages/security-report and https://bugcrowd.com/engagements/wyze
policy:
- https://www.wyze.com/pages/wyzes-vulnerability-disclosure
- https://global.wyze.com/pages/security-report
- https://bugcrowd.com/engagements/wyze
contact:
- security@wyze.com
security_txt: none
last_updated: 'January 2026'
bug_bounty:
  platform: Bugcrowd
  url: https://bugcrowd.com/engagements/wyze
  name: Wyze Bug Bounty
  out_of_scope_intake: wyzevpd@submit.bugcrowd.com
  rating_taxonomy: Bugcrowd Vulnerability Rating Taxonomy (VRT)
  scope_note: >-
    Wyze states it welcomes security researchers to help identify vulnerabilities in its
    web app and API.
process:
  steps:
  - id: reporting
    description: >-
      The Wyze Cybersecurity team becomes aware of a potential vulnerability; the reporter
      receives an acknowledgement and updates throughout handling.
  - id: evaluation
    description: >-
      The team confirms the vulnerability, assesses risk and impact, and assigns a
      processing priority.
  - id: solution
    description: >-
      A fix is developed with the product team; where a vulnerability is actively
      exploited a temporary containment may ship ahead of the full solution.
  - id: communication
    description: >-
      A security advisory is published for severe issues; less severe issues are
      communicated through other methods.
  slas:
    acknowledgement: within 48 hours (business days)
    status_updates: at least once every 7 days while under investigation or remediation
    resolution_target: approximately 3-4 weeks for confirmed vulnerabilities
  submission_guidance:
  - clear description of the issue
  - the affected product or service
  - steps to reproduce, if known
  - relevant screenshots, logs, or proof-of-concept information
  responsible_disclosure: >-
    Wyze asks that issues not be publicly disclosed until it has had a reasonable
    opportunity to investigate and address them, and commits to working in good faith
    with reporters.
  safe_harbor_note: >-
    Wyze states that reporting a security vulnerability will not affect product warranty
    or access to customer support. No formal legal safe-harbour clause is published on
    the disclosure page itself.
suspicious_activity_intake:
  url: https://www.wyze.com/pages/security-report
  contact: security@wyze.com
  requested_details:
  - detailed description of the issue
  - products and versions affected
  - device MAC address (ID)
  - account email address
  - time of the issue
  - submitted Log ID from the mobile app
evidence:
- source: https://global.wyze.com/pages/security-report
  kind: disclosure-policy
  http_status: 200
  keywords: [responsible disclosure, security@wyze.com, vulnerability, acknowledgement]
- source: https://www.wyze.com/pages/wyzes-vulnerability-disclosure
  kind: disclosure-page
  http_status: 200
  note: >-
    Shopify page rendered client-side with template suffix "bugcrowd" - it embeds the
    Bugcrowd program rather than serving static policy text.
- source: https://bugcrowd.com/engagements/wyze
  kind: bug-bounty
  http_status: 200
- source: https://www.wyze.com/pages/security-trust
  kind: security-hub
  http_status: 200
x-evidence:
  fetched: '2026-08-02'