Security fixes are applied to the latest published version.
Please do not publish sensitive security details in a normal GitHub issue. Use the repository's Security tab and choose Report a vulnerability to send a private report.
Include the affected version, expected impact, reproduction steps, and any relevant logs with controller identifiers and device paths redacted.
The project does not require administrator access and should not introduce drivers, services, telemetry, or internet-facing listeners.