Please do not disclose vulnerabilities, credentials, private user data, or reproduction details in a public issue.
Use GitHub's private vulnerability reporting flow. Include the affected component, impact, reproduction steps, and any suggested mitigation. You should receive an acknowledgement within five business days.
Security fixes target the current main branch and the current App Store or
TestFlight release candidate. Older builds are not independently supported.
Reports involving authentication, authorization, account deletion, private media, location, moderation, database policies, Edge Functions, partner access, or release credentials are especially important.