TeamViewer is a CVE Numbering Authority (CNA) and strictly follows the CVE rules for publishing vulnerabilities.
TeamViewer connects millions of people and machines around the world every day. The security of our software is an integral part of our corporate culture and our value proposition. With the Bug Bounty program, we want to motivate security researchers and ethical hackers around the world to check our products for security.
We make no compromises when it comes to the security of our application. We follow a security-by-design approach and regularly check the security of our software and infrastructure through code reviews, internal and external penetration tests, and automated measures. Despite all our efforts, 100% security of IT systems can never be guaranteed. We strive to offer the greatest possible security and are committed to pursuing this with transparency and dedication.
With our Bug Bounty Program, we open ourselves up to a wide circle of security experts (crowdsourced penetration testing) in order to offer our customers and users the best possible protection against data loss and cyber attacks.
Read the description and rules of the Bug Bounty program carefully.
Sign up for YesWeHack.
Create a vulnerability report. Add as much information as possible.
Wait for an answer. An initial response is usually sent within 1-2 working days. We will start the review immediately and get back to you afterwards.
If your report is accepted, you will receive an automatic payment of your bounty.
Our security experts review the report and determine the score in accordance with the CVSS 3 evaluation scheme.
Visit our VDP page for reporting vulnerabilities outside the Bug Bounty Program. Please note that no monetary rewards are paid there.
TeamViewer’s security team will investigate every submission in our Vulnerability Disclosure Program (VDP).