Skip to main content

Responsible Disclosure of Security Vulnerabilities

We're working with the security community to make iFixit safe for everyone.

Reporting security issues

If you've discovered a security vulnerability, we appreciate your help in disclosing it to us in a responsible manner.

We'll work with you to make sure that we understand the scope of the issue, and that we fully address your concern. If you believe you have discovered a vulnerability or have a security incident to report, please email security@ifixit.com. Please include a detailed summary of the issue you discovered. Be sure to include an email address where we can reach you in case we need more information.

Code of Conduct

Please act in good faith towards our users' privacy and data during your disclosure. When testing for vulnerabilities, please do not insert test code into popular public guides or threads. These guides are used by thousands of people daily, and disrupting their experience by testing for vulnerabilities is harmful.

Please, always make a new guide or ask a new question instead! If those actions are not possible, please delete all guides, comments, and posts when you have completed your testing and reporting.

We won't take legal or administrative action against you or your account if you act accordingly: White hat researchers are always appreciated.

Bug Bounty

We're happy to provide attribution to users who report valid security vulnerabilities. To be eligible for credit on this page and an iFixit gift certificate, you must:

  • Be the first person to responsibly disclose the bug.
  • Report a bug that could compromise our users' private data, circumvent the system's protections, or enable access to a system within our infrastructure.
  • Include reproduction steps specific to iFixit with exact urls, endpoints, etc.

Please do report:

  • Persistent Cross-Site Scripting (XSS)
  • Cross-Site Request Forgery (CSRF/XSRF)
  • Broken Authentication
  • Circumvention of our framework's privacy and permission models
  • Remote Code Execution

Please do not report:

  • Outdated versions of Wordpress with no known vulnerabilities
  • Username enumeration
  • Self-XSS
  • Missing DNS SPF records
  • Security problems with subdomains such as createsend.ifixit.com that are operated by third party services
  • Password policy “best practice” recommendations
  • Lack of email verification
  • Vulnerabilities which require preexisting privileged access to user data (e.g. session cookies, leaked passwords, etc.).
Important

Due to a significant recent increase in automated, AI-generated, and low-effort reports—especially those flagging generic best practices or issues identified via public “security scanner” tools—we are no longer able to respond to all submissions. If your report does not demonstrate a specific, real-world security vulnerability with tangible impact or a clear path to exploitation, you may not receive a response.

Our security team will assess each bug to determine if it qualifies. We do our best to respond to your reports in a timely manner. We aim to respond within 3 business days, however some reports take longer than others to investigate. We reply only during business hours (9AM-5PM PST, weekdays, excluding holidays).

Thanks!

Thank you for your help with keeping the iFixit community safe. We really appreciate it.

Here are people who have responsibly disclosed verified vulnerabilities in the past:

2026

2025

2024

2023

2022

2021

2020

2019

2018

2017

2016

2015

2014

2013

2012

2011

View Statistics:

Past 24 Hours: 11

Past 7 Days: 51

Past 30 Days: 224

All Time: 33,664