Please include what you were running, what you observed, and how to reproduce it. You will get an acknowledgement within a week. This is a spare-time project, so there is no promised fix deadline, but you will be told honestly what is intended and when.
Supported versions
| Version | Supported |
|---|---|
1.0.x | Yes |
| Earlier than 1.0 | No |
Security fixes land on main, and only the most recent release is
supported.
Threat model
Worth understanding before reporting, and worth knowing before you install it.
- It runs entirely locally No server and no accounts. The only third party it can contact is GitHub, to ask whether a newer release exists, and only if you switch that on when asked. See the privacy policy.
-
It executes two external binaries
scrcpyandadb, resolved from yourPATH, falling back to Homebrew and the Android SDK's standard locations. If an attacker can already write to a directory on yourPATHthey can already run code as you, and this app does not widen that. - It changes your default audio output device That is the documented mechanism by which it works, not a side effect. scrcpy plays to the default output and cannot be told to use a specific device.
-
The config file is sourced as shell
~/.config/pixel-audio-bridge/configis read withsource, so anyone who can write that file can execute code as you. It lives in your home directory under your own permissions. Treat it as you would~/.zshrc. - It is unsigned and un-notarized by design You build it from source yourself, so there is no binary to trust and no Gatekeeper prompt to click through.
Known accepted risks
These are documented rather than fixed, because they are inherent to how the thing works. Both appear on the site and in the README as well.
Wireless ADB widens your phone's exposure.
pab enable-wireless turns on Android Debug Bridge over TCP. While that is
enabled, any host on the same network that can reach your phone may attempt to connect
to it, subject to Android's own authorisation prompt. This is inherent to ADB. It resets
when the phone reboots, and USB avoids it entirely while also being faster.
The output watchdog is not instantaneous. When the output device changes mid-stream, playback is killed within about half a second rather than immediately, so audio may briefly reach another device in that window. This is a consequence of scrcpy having no way to target a specific output device.
Out of scope
Vulnerabilities in scrcpy or
adb belong upstream, since both are installed separately and are not
redistributed here. Please report those to their own projects.