Please use GitHub's private vulnerability-reporting form:
Report a vulnerability privately
Do not open a public issue for an unpatched vulnerability. Include the affected version, macOS version, impact, and minimal reproduction steps. Do not attach personal documents, extracted content, credentials, or other sensitive data. Synthetic samples are strongly preferred.
Nabeegh will acknowledge a report within seven days and coordinate disclosure after a fix is available. If the private form is unavailable, open a public issue containing no exploit details or sensitive data and ask for a private reporting channel.
FileMorrow is designed to process evidence locally with Apple Intelligence. Changes that add networking or analytics require explicit user consent and clear documentation.