| Version | Status |
|---|---|
| 0.x.x | ✅ Active development — security patches applied to the latest testing release. |
Do not open a public issue for security vulnerabilities. Please report them privately.
- Go to the Security Advisories page.
- Click "Report a vulnerability".
- Provide a detailed report including:
- Vulnerability type and affected component.
- Steps to reproduce.
- Potential impact and exploitation vector.
- Suggested fix (if known).
Reports will be acknowledged within 48 hours.
- Report received — Maintainer acknowledges and begins triage.
- Verification — Issue is reproduced and impact assessed.
- Patch development — Fix is developed, tested, and reviewed.
- Release — Fixed version is published via the standard release process.
- Public disclosure — After the fix is released, the vulnerability may be disclosed publicly.
This policy covers:
- The Android hook engine (Xposed/LSPosed module)
- The companion Android app
- The PC Designer tool
- The KMP shared core
- The build and deployment pipeline
- Issues caused by rooted device configuration (custom ROMs, kernel modifications)
- Ghost tap behavior caused by physical hardware damage beyond the tool's mitigation scope