Security fixes are provided for the latest published minor release. Users should upgrade to the newest patch before reporting a problem that may already be fixed.
GitHub private vulnerability reporting will be the reporting channel once this repository is public and maintainers have enabled it. Until then, that route is unavailable: do not open a public issue or send sensitive details through an unapproved channel. Enabling and testing private vulnerability reporting is a public-release prerequisite.
Include the affected version, platform and React Native version, a minimal reproduction, expected impact, and any mitigations you have already tested. We will acknowledge a complete report within five business days and coordinate disclosure after a fix is available. Please avoid accessing other users' data, disrupting services, or publishing details before that coordination is complete.
For the renderer's trust boundaries and host responsibilities, see docs/security.md.