Only the latest published release and the current default branch receive security updates.
Please do not disclose exploit details, device identifiers, logs, credentials, or signing material in a public issue.
Use Security → Report a vulnerability in this repository to submit a private report. If private reporting is unavailable, open a minimal issue requesting a private contact channel without including sensitive technical details.
Include the affected version, device/firmware combination, reproduction steps, impact, and any suggested mitigation. Reports will be acknowledged as time permits; this is a small, device-specific project with no guaranteed response deadline.
Reports about command or intent injection, privilege boundaries, exported Android components, unsafe root/ADB behavior, signing or release integrity, and rollback failures are especially useful. Physical access, an already-authorized ADB connection, or root access should be stated explicitly in the threat model.