Report a Security Issue
At Xperi, the security and privacy of our customers, partners, and users are top priorities. We are committed to maintaining a secure environment across our products, cloud services, and corporate systems, and we continually invest in security processes designed to identify, prevent, and remediate vulnerabilities. We value the contributions of the security research community and believe that responsible collaboration helps improve the overall security and resilience of our technology ecosystem.
If you believe you have identified a security vulnerability in a Xperi product or service, we encourage you to report it to us promptly and responsibly. Reports submitted in good faith will be reviewed by our security team, who will investigate the issue, determine its impact, and develop appropriate remediation measures when necessary. We are committed to working constructively with researchers throughout the disclosure process and to addressing validated vulnerabilities in a manner that helps protect our customers, users, and business operations.
Please report suspected security vulnerabilities affecting an Xperi product, service, website, application, cloud service or corporate system.
Examples may include vulnerabilities that could allow unauthorized access, disclosure of information, modification of data, disruption of a service or other unintended security impacts.
Please provide as much detail as possible so Xperi’s security team can evaluate and reproduce the issue. Helpful information includes:
-
- A clear description of the vulnerability
- The affected product, service or system
- The product version, model, build or affected URL
- Steps required to reproduce the issue
- Proof-of-concept code, screenshots, logs or supporting files
- The potential impact, if known
- Your contact information
Complete and detailed reports help the team assess potential vulnerabilities more efficiently.
Your submission will be sent to Xperi’s security team for review. The team will evaluate the information provided, attempt to reproduce the issue, assess its potential impact and determine whether remediation is required.
Xperi may contact you for additional information during the investigation.
Xperi aims to acknowledge reports submitted in good faith within five business days and evaluate and triage the issue within 10 business days.
The time required to fully investigate and resolve a vulnerability will depend on its severity, complexity and potential impact.
Xperi intends to keep reporters informed throughout the disclosure process when appropriate.
Updates may include confirmation that the issue is being investigated, requests for additional information and notification when remediation or coordinated disclosure steps have been completed.
Xperi aims to resolve validated vulnerabilities before they are publicly disclosed whenever possible.
The general target for coordinated disclosure is within 90 days. However, the timeline may be adjusted based on the severity or complexity of the issue, evidence of active exploitation, or the need to coordinate with third-party vendors or other affected organizations.
Please coordinate any planned public disclosure with Xperi’s security team.
The following activities are not covered by the Xperi Vulnerability Disclosure Program:
- Testing systems that are not owned or operated by Xperi
- Social engineering or phishing campaigns
- Denial-of-service or distributed denial-of-service testing
- Attempts to gain physical access to Xperi facilities, systems or equipment
Please avoid activities that could disrupt services, damage data or affect other users.
Submit a report or inquiry before performing additional testing.
Describe the affected product or system, the activity you are considering and the potential issue you have identified. Xperi’s security team can review the information and provide appropriate guidance.
Yes. The vulnerability reporting form allows you to include supporting files such as screenshots, logs, code samples and proof-of-concept materials.
Please include only information that is relevant to the reported issue and avoid submitting unnecessary personal, confidential or third-party information.
No. The Xperi Vulnerability Disclosure Program provides a coordinated process for reporting and investigating potential security vulnerabilities, but it does not currently offer bounties or monetary rewards.
Yes. The form may be used to report suspected vulnerabilities affecting Xperi and its products, services and brands.
Please identify the affected brand, product, service or system as clearly as possible in your submission.
Submit a Vulnerability Report
Please provide as much detail as possible. Information submitted through this form will be sent directly to Xperi’s security team for review.