If you discover a security vulnerability in Zepp OS Screen Reader — for example, an issue involving the BLE Braille display connection, the local Wi-Fi sideload/preview process, or handling of notification data — please do not open a public GitHub issue.
Instead:
- Open a private report via GitHub's Security Advisories feature for this repository, or
- Contact a maintainer directly through their GitHub profile if advisories aren't available.
Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce, if possible
- Any relevant device/version information
- We'll acknowledge your report as soon as possible.
- Since this project is maintained with limited resources, response time may vary — but security reports are treated as a priority over feature work.
- We'll aim to keep you informed as the issue is investigated and, where applicable, credit you in the fix's release notes (unless you prefer to remain anonymous).
As a rapidly evolving project, only the latest release on main is actively supported with security fixes.
Thank you for helping keep ZSR and its users safe.