Skip to content

Security: darshi1337/apogee

SECURITY.md

Security Policy

Reporting a Vulnerability

Please don't open a public issue for security or privacy vulnerabilities.

Report it privately, either way works:

Apogee is maintained by one person in their spare time, so please expect a first reply within about a week rather than within hours. You’ll get an acknowledgement, an assessment of whether it's reproducible, and a fix timeline. If you want credit in the release notes and the advisory, say so and tell me how you’d like to be named.

What Counts

Apogee’s central claim is that page content, summaries, and answers never leave your device, except to your own Ollama or llama.cpp server over loopback, plus the documented fetches listed in PRIVACY.md (model weights, site transcripts/subtitles/threads, and the SponsorBlock hash-prefix lookup). Anything that breaks that claim is a vulnerability here, even if it wouldn’t be one in an ordinary extension. For example:

  • Page content, extracted text, or a generated summary reaching any host other than the documented ones (127.0.0.1 / localhost for local inference; Hugging Face, YouTube, Bilibili, Bluesky, and SponsorBlock endpoints as described in PRIVACY.md)
  • A web page reading data belonging to another page through the extension, or reaching extension-privileged APIs
  • Bypassing extension sender checks (sender.id, tab-origin and port-sender validation) to invoke background actions from untrusted web pages
  • Polluting DOM global scope objects or exploiting content script execution contexts
  • Cached summaries or extracted content being readable by something other than the extension, or persisting for a URL that isSensitiveUrl should have excluded
  • Prompt injection from page content that escapes the grounding rules to make the model exfiltrate data or act outside summarizing (injection that merely produces a wrong or silly summary is a bug, not a vulnerability)
  • Anything letting an attacker widen the extension’s permissions or host access

Please do report a mismatch between what the docs promise and what the code does, even if nothing is exploitable yet. The manifest, the README’s Privacy section, PRIVACY.md, and STORE-LISTING.md are supposed to describe the same permission set, and a drift between them is exactly the kind of thing that turns into a real problem later.

What Doesn't

  • Vulnerabilities in a model’s output: a local model producing wrong, offensive, or hallucinated text is a quality issue, not a security one
  • Anything requiring the attacker to already have local access to your machine, your browser profile, or your unlocked extension storage
  • Reports against your own Ollama instance's configuration, which is outside what this extension controls
  • Automated scanner output with no working proof of concept

Accepted Risks

  • image-size HIGH advisories in dev tooling (GHSA-w3rx-r6r6-pgpr, GHSA-5p2g-fcmc-qvqq). The vulnerable ICNS/JXL/HEIF parsers reach us only through web-extaddons-linter, which pins image-size@2.0.2 exactly, and no fixed upstream release exists. The upstream repo is archived (June 2026) and will not publish a fix from GitHub, so the watch items are a revival published to npm, or addons-linter dropping the dependency. Exploiting it needs a malicious image inside this repo, which already means commit access, and only affects the machine running the linter; the shipped extension never bundles it (npm audit --omit=dev is clean). Accepted until one of those happens; re-check on every dependency bump.

Supported Versions

Only the latest released version gets fixes. Apogee ships through the Chrome Web Store and Firefox Add-ons, which auto-update, so “upgrade to the current version” is the remedy for anything reported against an older one.

There aren't any published security advisories