This project is developed against Chainway C5 and compatible UHF RFID handhelds. Only the latest release on main receives fixes.
Please do not open a public issue for security problems.
Use GitHub's private channel instead: Security → Report a vulnerability. Reports there are visible only to the maintainers.
If the private form is unavailable, contact the maintainer — @maximkr.
- app version (from the release page or
versionNameinapp/build.gradle.kts); - device model and Android version;
- steps to reproduce;
- what an attacker gains;
- whether physical access to the device or proximity to the RFID reader is required.
- acknowledgement — within 5 business days;
- initial assessment — within 14 days;
- fix and advisory — by agreement, depending on severity.
Please keep details private until a fix is released.
Relevant areas for this app:
- unintended tag writes — in particular anything that could overwrite EPC memory of neighbouring tags;
- handling of scanned barcode data before it reaches the tag;
- exported Android components (activities, services, receivers) reachable by other apps on the device;
- permission and intent handling;
- data written to logs or exported files.
- RFID protocol weaknesses themselves. EPC Gen2 tags are, by design, readable and often writable by anyone with a reader in range. This is a property of the standard, not a defect in this app.
- Vendor SDK internals.
app/libs/DeviceAPI_ver20230301_release.aaris a proprietary binary supplied by Chainway. Issues inside it must be reported to the vendor; we can only work around them. - Physical access attacks on an unlocked device.