Report vulnerabilities privately through GitHub security advisories. Do not open a public issue.
Include:
- the OpenSpatial version and the macOS version;
- what an attacker can do and what they need;
- steps or a proof of concept that reproduces it.
You will get an acknowledgement within seven days. Please keep the report private until a fix is released.
Only the latest release receives security fixes.
In scope: the audio driver and its installation with administrator rights, the download of the AI surround model, camera and microphone use, and the release artifacts.
Out of scope: an attacker who already controls the Mac or its administrator account.