Aerial has one active release line. Security fixes are made against the latest release; older versions are not patched separately.
Please do not open a public GitHub issue for security vulnerabilities.
Instead, report it privately using GitHub's private vulnerability reporting, or by emailing:
Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce it
- The Aerial version or commit affected
You should expect an initial response within 5 business days. If the report is confirmed, a fix will be prepared before any public disclosure. Please allow time for a fix to be released before disclosing the issue publicly.
Aerial does not include advertising, analytics, tracking SDKs, Firebase, Crashlytics, Google Play Services, or user accounts (see PRIVACY.md). Reports about third-party radio stream providers or logo hosts reached by the app are outside this policy's scope — please report those directly to the operator concerned.