Only the newest Browser3 release listed on the official release page is supported.
Do not open a public issue for a suspected vulnerability. Email radekcisar77@gmail.com with the subject Browser3 security report and include:
- the affected Browser3 version and archive SHA-256;
- operating-system and reproduction details;
- the expected and observed security impact;
- a minimal proof of concept, if it can be shared safely.
Do not include credentials, personal data, or third-party secrets. Encrypt sensitive attachments to the public release key when practical.
The maintainer aims to acknowledge a complete report within 7 days and provide an initial assessment within 14 days. These are targets, not a support-level agreement. There is currently no bug-bounty program.
Test only systems, accounts, and data you own or have explicit permission to assess. Do not exploit a vulnerability beyond what is needed to demonstrate impact, and allow reasonable time for remediation before public disclosure.