Brewser Docs
Support & Limitations

Security Disclosure

Reporting a security vulnerability in Brewser

If you've found a security vulnerability in the Brewser runtime, platform, or update mechanism, we want to hear about it — responsibly.

Please do

  • Report privately first. Give us a chance to fix an issue before it's public.
  • Include enough to reproduce: what you did, what happened, and the impact.
  • Give us reasonable time to respond and ship a fix before disclosing publicly.

Please don't

  • Don't publish exploit details, proofs-of-concept, or working exploits publicly before a fix is out.
  • Don't access, modify, or exfiltrate other users' data, or disrupt the service, while testing.

In scope

  • The Brewser runtime and its handling of untrusted app code.
  • The self-update mechanism (signed, forward-only).
  • The platform / submission pipeline, accounts, saves, and leaderboards.

App-level bugs (an individual catalogue app misbehaving) aren't security vulnerabilities in Brewser itself — report those as ordinary bugs.

How to report

Report privately to the Brewser maintainer through brewser.io — please don't open a public issue for a security vulnerability. We aim to acknowledge reports promptly and will keep you updated as a fix is worked out.

On this page