Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

China’s network-product vulnerability rules, reported to take effect on September 1, 2021, require vulnerabilities to be reported to Chinese authorities while allowing disclosure to the affected product’s manufacturer. The rules could give state actors earlier access to flaws, but available reporting does not establish how many vulnerabilities have been stockpiled or whether attacks have increased.

What do China’s vulnerability-disclosure rules require?

SecurityWeek reported on July 14, 2021, that the rules were issued by the Cyberspace Administration of China together with police and industry ministries, and would take effect on September 1, 2021. They apply to vulnerabilities found in network products. Under the report’s account, a person who discovers one must report it to Chinese authorities and may not sell or disclose it to an outside third party, except for the affected product’s manufacturer.

The reporting does not specify a disclosure deadline or establish how authorities handle every submission. It also does not support treating the rule as proof that every reported flaw is automatically passed to a particular government agency.

Can Chinese researchers still report flaws to foreign companies?

The manufacturer exception matters: it leaves room to report a vulnerability to the company whose product is affected, including a company based outside China. China Trade Monitor describes expert interpretation of the rule as permitting reports to product companies and restricting trade in cyber arms rather than barring vendor disclosure. That is an interpretation, not a definitive court ruling.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Permission to notify a manufacturer does not settle how quickly a researcher will do so in practice. SecurityWeek noted uncertainty about whether Chinese researchers would promptly alert Western vendors. If a researcher reports a flaw to authorities first and delays vendor notification, Chinese actors could learn of it before the company can prepare a fix. The reporting does not establish how often that sequence occurs.

How might the rules affect China’s zero-day stockpile?

A zero-day is a software flaw that a vendor has not yet had a chance to fix; when an attacker exploits it before a patch is available, defenders have limited time to respond. Requiring researchers to report discoveries to authorities could give the Chinese state access to some flaws earlier than it would otherwise have. That creates a potential intelligence and operational advantage, but the size of any resulting stockpile is unknown.

SecurityWeek quoted Jake Williams, co-founder and CTO at BreachQuest, as saying the government would “almost certainly funnel these vulnerabilities to Chinese government threat actors.” He cautioned that this might not increase attack volume, though it could increase attack sophistication, and noted that Chinese government organizations could also use the information defensively to mitigate flaws in their own systems. Joseph Carson, then chief security scientist and advisory CISO at ThycoticCentrify, expected the government to weaponize discovered vulnerabilities and said the rules would narrow researchers’ prior flexibility in sharing their work.

Potential use of early access Possible effect What the reporting establishes
Offensive intelligence State-linked operators could use a flaw before a vendor patch is available, potentially making attacks more sophisticated. SecurityWeek reports this as a concern and quotes experts’ assessments; it provides no measured increase in attacks or proof that every flaw is transferred to an operator.
Defensive mitigation Chinese government organizations could identify and patch vulnerable systems they use. Williams raised this as a possible defensive benefit; the reporting does not quantify its effect.

SecurityWeek placed the rule alongside Article 7 of China’s 2017 National Intelligence Law, which requires Chinese nationals to support, assist, and cooperate with national intelligence efforts. It also named the Ministry of State Security and the People’s Liberation Army Strategic Support Force in the context of state-affiliated advanced persistent threat groups. That context does not demonstrate that a particular vulnerability is delivered to either agency.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What could change for bug bounties and Pwn2Own?

Bug-bounty programs pay researchers for reporting flaws to participating organizations. The restriction on selling or giving vulnerability knowledge to outside third parties could limit a researcher’s ability to sell a finding to a higher-paying intermediary, while the manufacturer exception leaves a route for vendor disclosure. The report does not establish how any particular bounty program has changed its eligibility or payment rules in response.

SecurityWeek also raised the possibility that Chinese participation in Pwn2Own and similar competitions could decline if researchers cannot freely transfer or sell what they discover. Williams described a longer-term trade-off: in the short term, the state may gain access to findings, but researchers who have fewer ways to profit at home could leave, potentially weakening China’s research community over time. These are possible effects, not measured outcomes reported in the coverage.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is known—and what remains unproven?

  • Reported milestone: SecurityWeek’s July 14, 2021 report said the rules would take effect September 1, 2021.
  • Disclosure framework: the report says researchers must report network-product vulnerabilities to Chinese authorities and may disclose them to the affected manufacturer, but not to other outside third parties.
  • Strategic concern: authorities may gain earlier access to vulnerabilities that could have offensive or defensive value.
  • Unmeasured outcomes: the cited coverage gives no authoritative count of China’s zero-day stockpile, no measured attack-volume increase, and no current enforcement statistics.

Those limits mean the rules support a concern about state access, not a verified claim that China has built a larger stockpile or that attacks have risen because of the policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.