Security Bulletins

Zepp Health publishes security advisories and notices for smartwatches and IoT devices (software, hardware, firmware), detailing newly discovered vulnerabilities, their risk impacts, and remediation plans.

Quarterly Updates: Zepp Health will provide quarterly updates on security notices until all security issues are resolved.

Security Advisory Scope

Disclosure decisions are based on a risk-based evaluation and documented for traceability.

We Publish When
  • Vulnerabilities affect supported apps, firmware, or open-source components
  • Vulnerabilities have significant security impact (high or critical severity)
  • User action or awareness is required
  • Vulnerabilities are already publicly known or actively exploited
We May Withhold When
  • Disclosure could introduce unacceptable risk with no available mitigation
  • The vulnerability affects end-of-life products with no remediation path
  • The vulnerability does not apply to real-world deployments
  • Legal, regulatory, or contractual restrictions apply

Advisory Content

Each published security advisory may include the following information, presented in a clear and structured format.

  • Vulnerability description and technical summary
  • Affected products, components, and versions
  • Severity rating and impact assessment (confidentiality, integrity, availability)
  • Vulnerability identifiers — CVE numbers, advisory IDs, or internal tracking references
  • Exploitation conditions required to trigger the vulnerability
  • Available mitigations, workarounds, or security updates
  • Recommended actions for users
  • Publication date and latest revision date
Note: Sensitive details that could facilitate active exploitation may be withheld until appropriate mitigations are widely available. Multiple vulnerabilities may be consolidated into a single advisory where appropriate. All disclosures follow the Coordinated Vulnerability Disclosure (CVD) process.
Machine-readable format: Advisories are also published in CSAF v2.0 JSON (ISO/IEC 20153 aligned) for automated vulnerability management. Files are validated for JSON syntax, schema consistency, and required field completeness prior to publication. Available at https://src.zepp.com/advisories/<advisory-id>.json

Published Security Advisories

A list of resolved vulnerabilities with publicly available security advisories.

Published security advisories with severity, affected products, and status
Advisory ID Title Severity Affected Products Date Status CSAF
Loading advisories…