Security Bulletins

Zepp Health publishes security advisories and notices for smartwatches and IoT devices (software, hardware, firmware), detailing newly discovered vulnerabilities, their risk impacts, and remediation plans.

Quarterly Updates: Zepp Health publishes security notices on a quarterly basis to keep users informed about the latest vulnerability disclosures and remediation status.

Security Advisory Scope

We publish security advisories based on a risk-based evaluation, and every disclosure decision is documented for traceability.

We Publish When
  • A vulnerability affects a published and supported app, embedded system, or open-source component
  • A vulnerability has significant security impact (high or critical severity)
  • User action or awareness is required
  • A vulnerability is already publicly known or actively exploited
Deferred Publication
  • Where a documented evaluation shows that the cybersecurity risk of full publication outweighs the security benefit, detailed disclosure may be delayed and the reason and planned publication conditions are recorded

Advisory Content

Each published advisory includes the following information, where applicable, presented in a clear and structured format.

  • Vulnerability description and technical summary
  • Affected products, components, and versions
  • Severity rating and impact assessment
  • Potential security impact on confidentiality, integrity, availability, and safety where relevant
  • Vulnerability identifiers — CVE numbers, advisory IDs, or internal tracking references
  • Exploitation conditions required to trigger the vulnerability
  • Available mitigations, workarounds, and security updates or patches
  • Recommended actions for users
  • Initial publication and latest revision dates
  • Contact information for vulnerability-related enquiries
Disclosure handling: Sensitive details that could facilitate active exploitation may be withheld until appropriate mitigations are widely available. Multiple vulnerabilities may be consolidated into a single advisory where sufficient information remains for stakeholders to assess impact and remediation status. Published advisories indicate whether a vulnerability is fixed, mitigated, partially addressed, or under investigation, and follow the Coordinated Vulnerability Disclosure (CVD) process.

Advisory Presentation and Readability

Advisories are presented in a clear, structured, and human-readable format so affected users, customers, integrators, and other stakeholders can understand the security impact and act.

Human-Readable Presentation
  • Written in clear, understandable language for the intended audience
  • Affected products, versions, and components presented in a structured, easily identifiable manner
  • Remediation instructions, mitigation guidance, or update references provided in an actionable format
  • Severity or risk information clearly identified
  • Consistent formatting — headings, sections, tables, and bullet points — to support readability and navigation
  • Essential security information does not depend on machine-readable formats or specialized tools
Machine-Readable Advisory Format

Machine-readable advisories complement, and do not replace, the human-readable security advisory. Each is generated and maintained in structured JSON (CSAF v2.0) and includes the following standardized sections:

  • Document metadata
  • Publisher and tracking information
  • Product tree and affected product identification
  • Vulnerability descriptions and identifiers
  • Product status information
  • Impact and severity details
  • Remediation and mitigation information
  • References to related advisories, CVEs, or external resources
Public address: Machine-readable advisories are published at https://src.zepp.com/advisories/<advisory-id>.json and validated for JSON syntax, schema consistency, and required field completeness prior to publication.

Exception to Vulnerability Publication

Vulnerabilities resolved through remediation are normally published. Publication is omitted only when all of the following conditions are met.

  • The vulnerability has been fully remediated
  • Deployment of the remediation is fully under the organization's control and requires no action by customers or users
  • No residual risk remains for users, and no user awareness, mitigation activity, configuration change, or security action is required
  • The vulnerability exists solely within a remote data processing solution, cloud service, or backend infrastructure component, and has been fully remediated before disclosure
Governance: Each omission decision is documented, justified, and approved by the PSIRT or authorized management personnel, and retained within our vulnerability management records.

Published Security Advisories

A list of resolved vulnerabilities with publicly available security advisories.

Published security advisories with severity, affected products, and status
Advisory ID Title Severity Affected Products Date Status CSAF
Loading advisories…