Shieldxy runs a system extension that sees new socket flows after filtering starts. A bug here is not a crashed window — it can stall a user's network or leak what they connect to. Reports are taken seriously and triaged ahead of features.
| Version | Supported |
|---|---|
| Latest release | Yes |
| Previous release | Security fixes only |
| Older releases | No |
Do not open a public issue for a security vulnerability.
Report it through GitHub Security Advisories. The report is visible only to maintainers until a fix ships.
Please include:
- What the vulnerability is, and which component it affects (container app, system extension, or the XPC channel between them)
- Steps to reproduce
- Affected versions and your macOS version
- What an attacker gains
You will get an acknowledgement within 72 hours and an assessment within seven days. Please give us 90 days before public disclosure, or less if we ship a fix sooner.
- Verdict bypass: traffic that should be blocked but is allowed
- Denial of service against the verdict path (
handleNewFlow) - Rule-snapshot tampering, or an unauthorized peer on the app ↔ extension XPC channel
- Leakage of observed hostnames or flow metadata into logs, exports, or crash reports
- Privilege escalation through the system-extension install or activation flow
- Resource exhaustion or malformed-input handling in rule import, snapshots, Ask state, statistics state, or the XPC event path
- Anything requiring an already-compromised machine or physical access
- Findings that need System Integrity Protection to be disabled
- Social engineering, or reports about services Shieldxy does not run
There is no telemetry, cloud reputation lookup, or Community account.
Flow analysis, risk scoring, optional GeoIP, rules, and history stay local.
Rules and history live in ~/Library/Application Support/; preferences use
macOS UserDefaults. When software updates are enabled, Sparkle contacts the
public HTTPS appcast and release asset hosts. Shieldxy records flow metadata and
byte counts, not request bodies or TLS plaintext.