If you discover a security vulnerability in Browser Hand, please do not open a public issue.
Instead, report it privately via GitHub Security Advisories. We aim to respond within 3 business days.
For urgent issues you may also email support@verygoodplugins.com.
The latest minor release on the default branch receives security updates. Older versions may be patched on a case-by-case basis.
We follow coordinated disclosure: we'll work with you on a fix and credit you in the release notes if you wish.
Browser Hand drives a real Chrome profile via a local extension and relay. Reports of interest include:
- Privilege escalation from untrusted page content into the extension / relay / host
- Cross-origin or tab-targeting mistakes that leak cookies or session data
- Local WebSocket relay authentication / binding issues (should stay loopback-only)
- Prompt-injection or agent-driven actions that bypass intended human-in-the-loop focus gates
- Supply-chain issues in install/postinstall binary download paths
Automation against third-party sites is the operator’s responsibility; please do not use security reports as a request to automate CAPTCHA/auth bypass.