Only the latest released version of FF-WebHID (the Firefox WebHID addon and daemon) receives security fixes. Please make sure you're running the latest release before reporting an issue.
If you discover a security vulnerability in FF-WebHID (addon, daemon, or the native messaging bridge), please do not open a public issue. Publicly disclosing a vulnerability before a fix is available could put existing users at risk.
Instead, please report it privately using GitHub Security Advisories.
When reporting, please include as much of the following as you can:
- A description of the vulnerability and its potential impact
- Steps to reproduce, or a proof of concept
- The affected component (addon, daemon, or native messaging host) and platform (Linux/Windows/macOS)
- Any relevant logs (with sensitive data redacted)
- The Firefox addon (background/worker/page scripts, daemon-side HID (Human Interface Device) report descriptor parser via the hidreport crate)
- The Rust daemon and native messaging host
- The WebSocket data plane and its authentication mechanism
- The HID device blocklist (FIDO (Fast IDentity Online)/U2F security key protections; keyboard/mouse access is gated by OS permissions)
New reports are acknowledged within a few days, and you'll receive updates as the issue is investigated and fixed. Once a fix is released, you'll be credited in the release notes unless you prefer to stay anonymous.
Thank you for helping keep FF-WebHID and its users safe.