VTech Coordinated Vulnerability Disclosure Policy

Date: 2026-09-11

1. Purpose and commitment

VTech is committed to helping protect the security, safety and privacy of customers and users of VTech products with digital elements. This Policy establishes VTech’s coordinated vulnerability disclosure process for receiving, assessing, remediating and, where appropriate, disclosing information about potential vulnerabilities reported by internal and external sources.

This Policy supports VTech’s vulnerability-handling obligations under applicable law, including Regulation (EU) 2024/2847 (the Cyber Resilience Act or CRA), where applicable. It does not replace VTech’s internal product-security, incident-response, regulatory-notification, software-update, privacy or supplier-management procedures.

2. Scope

This Policy applies to potential vulnerabilities affecting VTech products with digital elements and related services made available by VTech, including relevant hardware, software, firmware, mobile applications, online services and remote data-processing solutions that are designed or developed by or on behalf of VTech and are necessary for those products to perform their functions.

This Policy does not authorise testing of assets owned or controlled exclusively by third parties. However, where a report concerns a third-party component, library, service or supplier product incorporated into or necessary for a VTech product, VTech may coordinate with the relevant supplier, maintainer, computer security incident response team (CSIRT), The European Union Agency for Cybersecurity (ENISA), competent authority or other appropriate party to validate, remediate and disclose the vulnerability.

3. Good-faith research and authorisation

Subject to this Policy and applicable law, VTech authorises good-faith security research directed solely at identifying and reporting potential vulnerabilities in in-scope assets. VTech will not knowingly pursue civil claims or refer such good-faith, authorised research for law-enforcement action solely because of that research.

This authorisation applies only where the researcher complies with this Policy, acts proportionately to avoid harm, and promptly reports the vulnerability to VTech. It does not authorise conduct that is unlawful, causes or risks material harm, infringes third-party rights, or is outside the stated scope. VTech cannot waive rights held by third parties or override the requirements of applicable law.

If a researcher is uncertain whether proposed activity is within scope or authorised, the researcher should contact VTech before proceeding at .

4. Researcher rules

To participate in the coordinated vulnerability disclosure process, researchers must:

  • comply with all applicable laws and this Policy;
  • use only accounts owned by the researcher, designated test accounts, or accounts for which the researcher has express written permission;
  • avoid accessing, collecting, copying, altering, transmitting, retaining or deleting VTech, customer or user data, except to the minimum extent strictly necessary to demonstrate the vulnerability and only where lawful;
  • immediately stop further access or collection if personal, confidential or user data is inadvertently encountered, preserve only the minimum evidence necessary, and promptly notify VTech through a secure channel;
  • avoid interruption, degradation or destruction of services; denial-of-service, resource-exhaustion and similar testing are prohibited unless VTech expressly authorises them in writing;
  • not exfiltrate data, introduce malware, establish persistence, pivot to other systems, or exploit a vulnerability beyond the minimum needed to establish its existence;
  • not use social engineering, physical attacks, threats, extortion or coercion;
  • not publicly disclose vulnerability details before coordinating with VTech under section 7; and
  • keep vulnerability information confidential until VTech and the reporter agree a disclosure timetable, subject to applicable law and the public interest.

5. Reporting a vulnerability

Reports should be submitted to . Reports may be submitted anonymously.

Researchers should use the subject line “URGENT — suspected active exploitation” where they have a reasonable basis to believe that a vulnerability is being actively exploited or creates an immediate material risk to users.

To enable timely triage, reports should, where available, include:

  • identification of the affected VTech product, product version, component, firmware/software version, service, domain or application;
  • where relevant, the country or channel through which the product was purchased and the location in which the issue was observed;
  • a description of the vulnerability, its potential impact and any information indicating actual or suspected active exploitation;
  • clear, reproducible steps, proof-of-concept code, logs, screenshots or other evidence sufficient to validate the issue, while minimising disclosure of personal or confidential data;
  • any known mitigation, workaround, proposed fix, affected third-party component or related identifier; and
  • a secure contact method and any preferred acknowledgement or disclosure attribution, if the reporter wishes to be contacted or credited.

6. VTech handling process

On receipt of a report, VTech will:

  • acknowledge receipt as soon as reasonably practicable;
  • assess whether the report is within scope and whether it indicates suspected active exploitation, a severe incident or an urgent risk to users;
  • validate and analyse the issue, including its severity, affected products and versions, exploitability, potential impact, and any affected third-party components;
  • prioritise, develop, test and deploy appropriate corrective or mitigating measures, including security updates, workarounds, configuration changes, customer guidance or other remediation measures, as appropriate;
  • coordinate with affected suppliers, maintainers, CSIRTs, competent authorities and other relevant parties where necessary for effective remediation;
  • provide status updates to the reporter where reasonably practicable, taking account of the nature and sensitivity of the report; and
  • document assessment, remediation, disclosure and any decision to delay public disclosure in accordance with applicable internal procedures.

VTech aims to provide an acknowledgement within 24-hour upon receiving of a report and an initial triage outcome or material status update where reasonably practicable. Actual response and remediation times depend on severity, complexity, exploitability, affected products, availability of mitigations and the information provided.

7. Coordinated disclosure and security advisories

VTech asks reporters not to disclose vulnerability details publicly before VTech has had a reasonable opportunity to validate, assess and remediate the issue. VTech will work in good faith with the reporter to agree a coordinated disclosure timetable, taking into account exploitability, active exploitation, affected users, availability of mitigation, availability of a security update and the public interest.

Once a security update or other corrective measure is made available, VTech will share and publicly disclose information about the fixed vulnerability in an appropriate security advisory, unless VTech reasonably determines and documents that the cybersecurity risks of immediate public disclosure outweigh the security benefits. In that case, VTech may delay publication for no longer than necessary to manage those risks and, where appropriate, provide affected users a reasonable opportunity to apply the relevant patch or mitigation first.

A security advisory will, as appropriate, include:

  • a description of the vulnerability;
  • the affected product, component and version or version range;
  • the vulnerability’s impact and severity;
  • clear, accessible instructions enabling users to remediate or mitigate the issue; and
  • information about the relevant security update, workaround or other corrective measure.

VTech may acknowledge or credit a reporter in a security advisory only with the reporter’s consent and subject to applicable law, security considerations and the reporter’s stated preferences.

8. Regulatory reporting and urgent escalation

VTech will assess whether a report concerns an actively exploited vulnerability or a severe incident affecting the security of a VTech product with digital elements. Where applicable, VTech will make notifications through the CRA Single Reporting Platform and to the relevant recipients within the deadlines required by Regulation (EU) 2024/2847 and other applicable law.

This public reporting channel does not replace VTech’s regulatory-notification processes. VTech will consider, where applicable, to provide for an early-warning assessment and escalation capable of supporting, notification within 24 hours of awareness, a full notification within 72 hours, and a final report within 14 days for an actively exploited vulnerability, or within one month for a severe incident, covering the incident, its root cause and the mitigating measures taken.

VTech may report or share vulnerability or incident information with competent authorities, CSIRTs, ENISA, suppliers, maintainers, service providers or other appropriate parties where required by law or reasonably necessary to investigate, remediate, coordinate disclosure or protect users.

In addition to notifying the competent CSIRT and ENISA, VTech will inform affected users, without undue delay, that a vulnerability or incident has been identified that may affect the security of their product, together with any mitigation steps users can take, even where a permanent security update is not yet available.

9. Third-party coordination

Where a reported issue affects a third-party component, library, vendor or service, VTech may share the minimum necessary information with that party or an appropriate coordinator to support validation, remediation and coordinated disclosure. Where reasonably practicable, VTech will take account of the sensitivity of the report and the reporter’s contact preferences. VTech may make such disclosures without prior notice where necessary to protect users, comply with law or manage material cybersecurity risk.

10. Personal data and confidentiality

VTech will process personal data contained in vulnerability reports for vulnerability management, product security, incident response, regulatory compliance, legal obligations and the protection of VTech, its users and other affected persons. VTech will handle reports in accordance with its privacy policy.

Researchers should not include unnecessary personal data, confidential information, credentials or sensitive data in a report. VTech may share information contained in a report with relevant VTech personnel, group companies, service providers, affected suppliers or maintainers, CSIRTs, competent authorities or law-enforcement bodies where permitted or required by law and necessary for the purposes described in this Policy and the Privacy Notice.

11. Governance, review and contact

VTech will review the Policy regularly and following material changes to applicable requirements, VTech products, security operations or lessons learned from vulnerability handling.

VTech maintains internal roles, procedures, records, training and oversight arrangements to support implementation and enforcement of this Policy, vulnerability handling throughout relevant support periods, and continuous improvement of product security.

Questions about this Policy or uncertainty about authorised research should be sent to .

12. Legal notice

This Policy does not create a contractual obligation, waive any legal right or remedy, or authorise any activity outside the scope expressly stated in this Policy. Nothing in this Policy limits VTech’s ability to take action in relation to conduct that is unlawful, malicious, reckless, fraudulent, extortionate, harmful, or inconsistent with this Policy.