Security fixes apply to the current main branch and, after the first stable publication, the latest stable release. Development artifacts and superseded candidate builds are not supported releases.
Do not disclose a suspected vulnerability in a public issue, pull request, discussion, or attachment.
Use GitHub's Report a vulnerability control on this repository's Security page. Include the affected app version and commit, Android and System WebView versions, reproduction steps, impact, and a minimal non-sensitive test case when available.
Do not upload credentials, private molecular structures, medical data, release keys, or other confidential material. Use synthetic or minimized data.
The issue may belong to the Android host, Android System WebView, upstream Mol*, or an interaction between those layers. Report it here when the Android package or integration is involved; maintainers can coordinate upstream disclosure.