Security fixes are applied to the latest release and the main branch.
Please use GitHub's Report a vulnerability option under the repository's Security tab. Do not open a public issue containing exploit details, private device data, tokens, signing material, or notification content.
Include the affected version, reproduction steps, impact, and any suggested mitigation. You should receive an initial response within seven days.
Never commit Android signing keys, local.properties, access tokens, notification contents, device logs with personal information, or the proprietary Glyph Matrix SDK AAR.