To report a potential security vulnerability in a Winbond product, please contact the Winbond Product Security Incident Response Team at psrit@winbond.com. Due to their sensitive nature, Winbond strongly urges that emails regarding potential vulnerabilities are encrypted. Our PGP key can be found here.
Please be sure to include as much information about the issue as possible including
- As many details about the Winbond product as you can such as Part Number, Product Category (e.g., TrustME, Customized Memory Solution, Code Storage Flash Memory)
- A description of the issue with detailed steps or information on how to reproduce the problem
- Any supporting information (such as logs, crash dumps, packet captures and screenshots)
- References to known vulnerabilities with relevant CVE’s where applicable
Alternatively, you can use the form below to report a potential security vulnerability If you have other questions or are experiencing an issue related to the website (including website related security issues), please use this Contact us form to get in touch with our support team, as the current page is only for Product related security issues.
Please allow seven business days for an initial response