Report vulnerabilities privately through GitHub security advisories. Do not open a public issue.
Include:
- the affected app and version, and the platform and OS version;
- what an attacker can do and what they need (local access, a malicious website, a copied vault file);
- steps or a proof of concept that reproduces it.
You will get an acknowledgement within seven days. Please keep the report private until a fix is released.
Only the latest release receives security fixes.
In scope: the vault format and its encryption, unlock and recovery, the link between the Chrome extension and the Mac app, autofill on macOS and Android, and the release artifacts.
Out of scope: an attacker who already controls the unlocked device, its screen or clipboard; loss of a vault file that has no backup.