Security fixes are developed against the current default branch and included in the next applicable release. Older releases may not receive backports.
Do not disclose a vulnerability or sensitive macOS data in a public issue. Use GitHub's private vulnerability reporting option on this repository when it is available. If it is unavailable, open a public issue containing no exploit, credentials, personal data, private paths, or reproduction secrets and ask the maintainers to establish a private contact channel.
Include the affected version, macOS version, impact, and a minimal privacy-safe reproduction. Remove contact data, message content, calendar details, reminder content, photo metadata, note content, account names, and local identifiers.
The maintainers will acknowledge a usable report, assess its scope, and coordinate remediation and disclosure. Please do not publish details before a fix or agreed disclosure date is available.