UROVO Partner program offers you access to our industry-leading products and exclusive resources so you can grow faster and stronger. Submit an application to become a Urovo Partner today!
contact us
top

UROVO Product Security | PSIRT & Vulnerability Disclosure

2026-08-26 10:18:00
Source:Urovo
UROVO Product Security — Lite PSIRT Mockup
Product Security Incident Response Team

UROVO Product Security

UROVO’s Product Security Incident Response Team (PSIRT) receives, validates, coordinates, remediates and discloses security vulnerabilities affecting UROVO products.

Vulnerability Disclosure

From Report to Remediation

UROVO manages vulnerability remediation through a risk-based process and coordinates with relevant platform, chipset and component providers when required.

01

Report

Submit a potential vulnerability through UROVO’s official support or security channel.

02

Acknowledge

Receipt is normally acknowledged within 1 business day.

03

Assess

An initial assessment is normally completed within 5 business days.

04

Remediate

Confirmed issues are handled according to severity, product impact and available fixes or mitigations.

05

Disclose

Where appropriate, UROVO publishes relevant security information, fixes or mitigation guidance.

Target Remediation Timeframes

Risk-based remediation targets

Critical
90 days
Target remediation timeframe
High & Medium
120 days
Target remediation timeframe
Low
180 days
Target remediation timeframe
Vulnerability response begins when UROVO receives or otherwise identifies a potential vulnerability affecting its products. Initial intake and triage are not delayed pending final confirmation of product applicability. The remediation target begins when the vulnerability is confirmed as applicable to the relevant product. Remediation may include a security fix or an effective mitigation.

Where a vulnerability originates from Google, Qualcomm, or other third-party components based on proprietary or non-public source code, the actual remediation timeline depends on the availability of the applicable fix or remediation solution from the relevant provider. Where an applicable upstream fix is not yet available, UROVO will evaluate feasible mitigations or compensating measures based on product risk and will continue to track the issue as appropriate.

Timelines may also be affected by platform updates, certification requirements, or customer-specific validation.
Responsible Disclosure

How UROVO handles security reports

  • Issues are assessed according to confirmed impact and severity.
  • Reporters’ and customers’ information is protected during handling.
  • Public information focuses on affected scope, mitigation, updates and status changes.
  • Upstream dependencies are tracked when a fix depends on third-party components or platforms.
Security Updates

Android Security Patches

For device-specific Android security patch information, continue using UROVO’s current security patch page.

Open Security Patch Page

Security Advisories

Published vulnerability information

The following entries summarize security vulnerabilities selected for public disclosure. Select a CVE ID or source link to view the corresponding official security bulletin.

CVE Vulnerability / Component Severity Patch / Bulletin Source
CVE-2022-20197 EoP (Elevation of Privilege) — Framework Medium 2022-09 Android Security Bulletin
CVE-2022-20468 ID (Information Disclosure) — System Medium 2022-12 Android Security Bulletin
CVE-2022-20322 ID (Information Disclosure) — Framework Low 2022-09 (Android 13 initial release) Android 13 Security Bulletin
CVE-2022-20323 ID (Information Disclosure) — Framework Low 2022-09 Android 13 Security Bulletin
CVE-2023-20971 EoP (Elevation of Privilege) — Framework Medium 2023-06 (Pixel supplement) Pixel Security Bulletin
CVE-2023-21168 ID (Information Disclosure) — Framework Medium 2023-06 Pixel Security Bulletin
CVE-2023-21345 ID (Information Disclosure) — Framework Low 2023-10 (Android 14 initial release) Android 14 Security Bulletin
CVE-2013-0340 DoS (Denial of Service) — Android Runtime Low 2022-09 (Android 13 initial release) Android 13 Security Bulletin
CVE-2024-29784 EoP (Elevation of Privilege) — Pixel / lwis Medium 2024-06 Pixel Security Bulletin
CVE-2024-29778 ID (Information Disclosure) — Exynos RIL Medium 2024-06 Pixel Security Bulletin
CVE-2024-56427 EoP (Elevation of Privilege) — Mobile Network Modem Medium 2025-06 (Pixel) Pixel Security Bulletin
CVE-2025-32315 EoP (Elevation of Privilege) — Fingerprint Sensor Medium 2025-06 Pixel Security Bulletin
Report a Vulnerability

Contact UROVO Product Security

If you believe you have identified a potential security vulnerability affecting a UROVO product, please contact UROVO through the official security email and include the affected product/model, software or firmware version, issue description, reproduction steps and relevant evidence where available.

security@urovo.com

UROVO Product Security | PSIRT & Vulnerability Disclosure

2026-08-26 10:18:00
Source:Urovo
UROVO Product Security — Lite PSIRT Mockup
Product Security Incident Response Team

UROVO Product Security

UROVO’s Product Security Incident Response Team (PSIRT) receives, validates, coordinates, remediates and discloses security vulnerabilities affecting UROVO products.

Vulnerability Disclosure

From Report to Remediation

UROVO manages vulnerability remediation through a risk-based process and coordinates with relevant platform, chipset and component providers when required.

01

Report

Submit a potential vulnerability through UROVO’s official support or security channel.

02

Acknowledge

Receipt is normally acknowledged within 1 business day.

03

Assess

An initial assessment is normally completed within 5 business days.

04

Remediate

Confirmed issues are handled according to severity, product impact and available fixes or mitigations.

05

Disclose

Where appropriate, UROVO publishes relevant security information, fixes or mitigation guidance.

Target Remediation Timeframes

Risk-based remediation targets

Critical
90 days
Target remediation timeframe
High & Medium
120 days
Target remediation timeframe
Low
180 days
Target remediation timeframe
Vulnerability response begins when UROVO receives or otherwise identifies a potential vulnerability affecting its products. Initial intake and triage are not delayed pending final confirmation of product applicability. The remediation target begins when the vulnerability is confirmed as applicable to the relevant product. Remediation may include a security fix or an effective mitigation.

Where a vulnerability originates from Google, Qualcomm, or other third-party components based on proprietary or non-public source code, the actual remediation timeline depends on the availability of the applicable fix or remediation solution from the relevant provider. Where an applicable upstream fix is not yet available, UROVO will evaluate feasible mitigations or compensating measures based on product risk and will continue to track the issue as appropriate.

Timelines may also be affected by platform updates, certification requirements, or customer-specific validation.
Responsible Disclosure

How UROVO handles security reports

  • Issues are assessed according to confirmed impact and severity.
  • Reporters’ and customers’ information is protected during handling.
  • Public information focuses on affected scope, mitigation, updates and status changes.
  • Upstream dependencies are tracked when a fix depends on third-party components or platforms.
Security Updates

Android Security Patches

For device-specific Android security patch information, continue using UROVO’s current security patch page.

Open Security Patch Page

Security Advisories

Published vulnerability information

The following entries summarize security vulnerabilities selected for public disclosure. Select a CVE ID or source link to view the corresponding official security bulletin.

CVE Vulnerability / Component Severity Patch / Bulletin Source
CVE-2022-20197 EoP (Elevation of Privilege) — Framework Medium 2022-09 Android Security Bulletin
CVE-2022-20468 ID (Information Disclosure) — System Medium 2022-12 Android Security Bulletin
CVE-2022-20322 ID (Information Disclosure) — Framework Low 2022-09 (Android 13 initial release) Android 13 Security Bulletin
CVE-2022-20323 ID (Information Disclosure) — Framework Low 2022-09 Android 13 Security Bulletin
CVE-2023-20971 EoP (Elevation of Privilege) — Framework Medium 2023-06 (Pixel supplement) Pixel Security Bulletin
CVE-2023-21168 ID (Information Disclosure) — Framework Medium 2023-06 Pixel Security Bulletin
CVE-2023-21345 ID (Information Disclosure) — Framework Low 2023-10 (Android 14 initial release) Android 14 Security Bulletin
CVE-2013-0340 DoS (Denial of Service) — Android Runtime Low 2022-09 (Android 13 initial release) Android 13 Security Bulletin
CVE-2024-29784 EoP (Elevation of Privilege) — Pixel / lwis Medium 2024-06 Pixel Security Bulletin
CVE-2024-29778 ID (Information Disclosure) — Exynos RIL Medium 2024-06 Pixel Security Bulletin
CVE-2024-56427 EoP (Elevation of Privilege) — Mobile Network Modem Medium 2025-06 (Pixel) Pixel Security Bulletin
CVE-2025-32315 EoP (Elevation of Privilege) — Fingerprint Sensor Medium 2025-06 Pixel Security Bulletin
Report a Vulnerability

Contact UROVO Product Security

If you believe you have identified a potential security vulnerability affecting a UROVO product, please contact UROVO through the official security email and include the affected product/model, software or firmware version, issue description, reproduction steps and relevant evidence where available.

security@urovo.com