Do not open public issues for security-sensitive problems.
Report suspected vulnerabilities privately to the maintainers through your established internal security/contact channel. Include:
- affected component or file
- impact summary
- reproduction steps
- any proof-of-concept material
- whether the issue affects released candidates only or mainline development builds as well
Security-sensitive areas include:
- provider permission enforcement
- signer/runtime state handling
- profile storage and snapshot persistence
- message routing between content script, background, prompt, and the background-owned runtime
- WASM bridge boundaries
- Reports should be acknowledged promptly.
- Fixes should be validated with automated tests where practical.
- Public disclosure should wait until a fix or mitigation is available.