Report a Security Issue

At Xperi, the security and privacy of our customers, partners, and users are top priorities. We are committed to maintaining a secure environment across our products, cloud services, and corporate systems, and we continually invest in security processes designed to identify, prevent, and remediate vulnerabilities. We value the contributions of the security research community and believe that responsible collaboration helps improve the overall security and resilience of our technology ecosystem.

If you believe you have identified a security vulnerability in a Xperi product or service, we encourage you to report it to us promptly and responsibly. Reports submitted in good faith will be reviewed by our security team, who will investigate the issue, determine its impact, and develop appropriate remediation measures when necessary. We are committed to working constructively with researchers throughout the disclosure process and to addressing validated vulnerabilities in a manner that helps protect our customers, users, and business operations.

Report a Security Issue

Please report suspected security vulnerabilities affecting an Xperi product, service, website, application, cloud service or corporate system.

Examples may include vulnerabilities that could allow unauthorized access, disclosure of information, modification of data, disruption of a service or other unintended security impacts.

Please provide as much detail as possible so Xperi’s security team can evaluate and reproduce the issue. Helpful information includes:

    • A clear description of the vulnerability
    • The affected product, service or system
    • The product version, model, build or affected URL
    • Steps required to reproduce the issue
    • Proof-of-concept code, screenshots, logs or supporting files
    • The potential impact, if known
    • Your contact information

Complete and detailed reports help the team assess potential vulnerabilities more efficiently.

Your submission will be sent to Xperi’s security team for review. The team will evaluate the information provided, attempt to reproduce the issue, assess its potential impact and determine whether remediation is required.

Xperi may contact you for additional information during the investigation.

Xperi aims to acknowledge reports submitted in good faith within five business days and evaluate and triage the issue within 10 business days.

The time required to fully investigate and resolve a vulnerability will depend on its severity, complexity and potential impact.

Xperi intends to keep reporters informed throughout the disclosure process when appropriate.

Updates may include confirmation that the issue is being investigated, requests for additional information and notification when remediation or coordinated disclosure steps have been completed.

Xperi aims to resolve validated vulnerabilities before they are publicly disclosed whenever possible.

The general target for coordinated disclosure is within 90 days. However, the timeline may be adjusted based on the severity or complexity of the issue, evidence of active exploitation, or the need to coordinate with third-party vendors or other affected organizations.

Please coordinate any planned public disclosure with Xperi’s security team.

The following activities are not covered by the Xperi Vulnerability Disclosure Program:

  • Testing systems that are not owned or operated by Xperi
  • Social engineering or phishing campaigns
  • Denial-of-service or distributed denial-of-service testing
  • Attempts to gain physical access to Xperi facilities, systems or equipment

Please avoid activities that could disrupt services, damage data or affect other users.

Submit a report or inquiry before performing additional testing.

Describe the affected product or system, the activity you are considering and the potential issue you have identified. Xperi’s security team can review the information and provide appropriate guidance.

Yes. The vulnerability reporting form allows you to include supporting files such as screenshots, logs, code samples and proof-of-concept materials.

Please include only information that is relevant to the reported issue and avoid submitting unnecessary personal, confidential or third-party information.

No. The Xperi Vulnerability Disclosure Program provides a coordinated process for reporting and investigating potential security vulnerabilities, but it does not currently offer bounties or monetary rewards.

Yes. The form may be used to report suspected vulnerabilities affecting Xperi and its products, services and brands.

Please identify the affected brand, product, service or system as clearly as possible in your submission.

Submit a Vulnerability Report

Please provide as much detail as possible. Information submitted through this form will be sent directly to Xperi’s security team for review.

First Name
Last Name
Identify the product, website, application, cloud service, device or system where you discovered the potential vulnerability.
Provide a brief title that summarizes the potential vulnerability. Do not include sensitive technical details in the title.
Select the potential severity based on your current understanding. Xperi's security team will independently evaluate and classify the report.
Max. Dateigröße: 50 MB.
Help provide additional information for our team to help assess the entire scope of the vulnerability.
Include the affected software version, firmware version, model number, release number or build number, if known.
Provide the affected webpage, domain, API endpoint, application location, file path or other relevant system location.
Enter the date when you first identified the potential vulnerability.
Provide another preferred method of contact or any information that may help Xperi communicate with you.
Has This Issue Been Publicly Disclosed?
Indicate whether information about this vulnerability has already been published, shared publicly or disclosed to another organization.
Complete Submission(erforderlich)