UROVO Product Security | PSIRT & Vulnerability Disclosure
UROVO Product Security
UROVO’s Product Security Incident Response Team (PSIRT) receives, validates, coordinates, remediates and discloses security vulnerabilities affecting UROVO products.
From Report to Remediation
UROVO manages vulnerability remediation through a risk-based process and coordinates with relevant platform, chipset and component providers when required.
Report
Submit a potential vulnerability through UROVO’s official support or security channel.
Acknowledge
Receipt is normally acknowledged within 1 business day.
Assess
An initial assessment is normally completed within 5 business days.
Remediate
Confirmed issues are handled according to severity, product impact and available fixes or mitigations.
Disclose
Where appropriate, UROVO publishes relevant security information, fixes or mitigation guidance.
Risk-based remediation targets
Where a vulnerability originates from Google, Qualcomm, or other third-party components based on proprietary or non-public source code, the actual remediation timeline depends on the availability of the applicable fix or remediation solution from the relevant provider.
Timelines may also be affected by platform updates, certification requirements, or customer-specific validation.
How UROVO handles security reports
- Issues are assessed according to confirmed impact and severity.
- Reporters’ and customers’ information is protected during handling.
- Public information focuses on affected scope, mitigation, updates and status changes.
- Upstream dependencies are tracked when a fix depends on third-party components or platforms.
Android Security Patches
For device-specific Android security patch information, continue using UROVO’s current security patch page.
Published vulnerability information
Advisories can show the alert ID, affected product, severity, status, remediation guidance and publication date. For the lightweight version, this can start as a simple manually maintained list without search or filters.
Contact UROVO Product Security
If you believe you have identified a potential security vulnerability affecting a UROVO product, please contact UROVO through the official security email and include the affected product/model, software or firmware version, issue description, reproduction steps and relevant evidence where available.