Brewser Docs
Support & Limitations

Security Disclosure

Reporting a security vulnerability in Brewser

If you've found a security vulnerability in the Brewser runtime, platform, or update mechanism, we want to hear about it, responsibly.

Please do

  • Report privately first. Give us a chance to fix an issue before it's public.
  • Include enough to reproduce: what you did, what happened, and the impact.
  • Give us reasonable time to respond and ship a fix before disclosing publicly.

Please don't

  • Don't publish exploit details, proofs-of-concept, or working exploits publicly before a fix is out.
  • Don't access, modify, or exfiltrate other users' data, or disrupt the service, while testing.

In scope

  • The Brewser runtime and its handling of untrusted app code.
  • The self-update mechanism (signed, forward-only).
  • The platform / submission pipeline, accounts, saves, and leaderboards.

App-level bugs (an individual catalogue app misbehaving) aren't security vulnerabilities in Brewser itself. Report those as ordinary bugs.

How to report

Report privately to the Brewser maintainer through brewser.io. Please don't open a public issue for a security vulnerability. We aim to acknowledge reports promptly and will keep you updated as a fix is worked out.

On this page