Skip to content

Security: tamesystems/messageglass

SECURITY.md

Security policy

Supported versions

MessageGlass has not published its first tagged release. Security fixes currently target the latest commit on main.

Version Supported
main Yes
Older commits No

A release-specific support table will replace this section when tagged releases exist.

Report a vulnerability privately

Do not open a public issue for a vulnerability or attach real Messages data.

Use GitHub private vulnerability reporting to describe the problem. Include the smallest synthetic reproducer possible, affected commit or version, expected impact, and any mitigation you have identified.

Never submit a real chat.db, WAL file, message body, handle, GUID, attachment path, or screenshot of private conversation data. If the issue can only be reproduced with private data, describe its shape without including its contents and wait for coordinated guidance.

The maintainers will acknowledge a report as availability permits, investigate it privately, and coordinate disclosure after a fix is available. Please do not disclose the issue publicly before that process completes.

Security boundary

MessageGlass opens SQLite read-only and query-only, has no message-send API, and performs no network operations. Reading the live Messages database still requires Full Disk Access. That permission applies to the entire host process, and downstream code can transmit any data it reads.

Security reports are especially welcome for:

  • writes or mutations to the Messages database;
  • parser panics, excessive allocation, or resource-limit bypasses;
  • content exposure through doctor or error messages;
  • cursor confusion that crosses a requested chat boundary;
  • unsafe handling of attachment paths;
  • dependency or vendored-code vulnerabilities.

There aren't any published security advisories