Product Security

Cirrus Logic is committed to protecting the security of our products. If you believe you have found a product security vulnerability or become aware of a product security incident, please report it to the Cirrus Logic Product Security Incident Response Team (PSIRT).

Cirrus Logic’s product security scope includes silicon devices, firmware, software, device drivers, and tools. It does not include the external Cirrus Logic website or internal IT infrastructure.

Responsible reports from security researchers, customers, partners, and other members of the security community are valued. Cirrus Logic does not participate in bug bounty programs.

Report a Security Vulnerability

Submit a Report

Reports with enough technical detail to reproduce the issue can usually be evaluated more quickly. Please include:

  • Your name and preferred contact information
  • The affected Cirrus Logic product, component, or device
  • Product identifiers, part numbers, and affected versions
  • Technical Details:
    • A clear description of the product vulnerability or incident and its potential impact
    • Reproduction steps or proof-of-concept code, if available
    • Relevant logs, screenshots, test results, or other supporting evidence
    • The environment or configuration in which the issue was observed
  • Any known or suspected exploit activity
  • Any planned public disclosure date or related CVE information.

Submit reports in English when possible. Please limit any personal data or sensitive information included in your report to what is necessary to investigate the issue. Do not include passwords.

What to Expect

Cirrus Logic typically acknowledges reports within one business day. Remediation is product-specific and depends on the assessed risk and the difficulty of developing a fix.

For general market products, public drivers, and development tools, the public disclosure timeline is discretionary and grounded in “Do No Harm” principles. Coordinated disclosure timelines are negotiable. In most cases, Cirrus Logic will communicate directly with affected customers.

For product questions, defects, or technical assistance that are not security-related, contact Cirrus Logic Customer Support.

Contact

Cirrus Logic PSIRT
psirt@cirrus.com

Any personal data provided in connection with a product security vulnerability or incident report will be handled in accordance with our Privacy Policy.