Support & Limitations
Security Disclosure
Reporting a security vulnerability in Brewser
If you've found a security vulnerability in the Brewser runtime, platform, or update mechanism, we want to hear about it — responsibly.
Please do
- Report privately first. Give us a chance to fix an issue before it's public.
- Include enough to reproduce: what you did, what happened, and the impact.
- Give us reasonable time to respond and ship a fix before disclosing publicly.
Please don't
- Don't publish exploit details, proofs-of-concept, or working exploits publicly before a fix is out.
- Don't access, modify, or exfiltrate other users' data, or disrupt the service, while testing.
In scope
- The Brewser runtime and its handling of untrusted app code.
- The self-update mechanism (signed, forward-only).
- The platform / submission pipeline, accounts, saves, and leaderboards.
App-level bugs (an individual catalogue app misbehaving) aren't security vulnerabilities in Brewser itself — report those as ordinary bugs.
How to report
Report privately to the Brewser maintainer through brewser.io — please don't open a public issue for a security vulnerability. We aim to acknowledge reports promptly and will keep you updated as a fix is worked out.
Related
- Security Review — how submitted apps are scanned.
- Getting Help — for non-security bugs.

Brewser Docs