Last updated 1 August 2026

Security

Please do not open a public issue for a security problem

Reporting a vulnerability

Use GitHub's private reporting. It creates a draft advisory that only you and the maintainer can see, so the details stay unpublished while a fix is prepared.

Report a vulnerability

Please include what you were running, what you observed, and how to reproduce it. You will get an acknowledgement within a week. This is a spare-time project, so there is no promised fix deadline, but you will be told honestly what is intended and when.

Supported versions

VersionSupported
1.0.xYes
Earlier than 1.0No

Security fixes land on main, and only the most recent release is supported.

Threat model

Worth understanding before reporting, and worth knowing before you install it.

Known accepted risks

These are documented rather than fixed, because they are inherent to how the thing works. Both appear on the site and in the README as well.

Wireless ADB widens your phone's exposure. pab enable-wireless turns on Android Debug Bridge over TCP. While that is enabled, any host on the same network that can reach your phone may attempt to connect to it, subject to Android's own authorisation prompt. This is inherent to ADB. It resets when the phone reboots, and USB avoids it entirely while also being faster.

The output watchdog is not instantaneous. When the output device changes mid-stream, playback is killed within about half a second rather than immediately, so audio may briefly reach another device in that window. This is a consequence of scrcpy having no way to target a specific output device.

Out of scope

Vulnerabilities in scrcpy or adb belong upstream, since both are installed separately and are not redistributed here. Please report those to their own projects.