RESPONSIBLE VULNERABILITY
DISCLOSURE PROGRAM.
We welcome independent security researchers, reverse engineers, and developers to audit our platform. We commit to transparent coordination, timely patches, and legal safe harbor.
Scope of Research
The following targets are strictly in scope for security evaluations:
- Kernel Security: Yama LSM bypasses, privilege escalation, or heap overflows in
kernel/oneplus/msm8996. - Hardware Controls: Bypasses of USB Restricted Mode on locked devices (
deny_new_usb). - Update Pipeline: Package signature spoofing, certificate validation bugs in
otacerts.zipor CYRONIX Recovery. - Firewall Subsystem: Netfilter UID leakages or per-app traffic bypasses.
- Platform Infrastructure: Vulnerabilities in
cyronixos.cyronixsecurity.comor OTA distribution endpoints.
Out of Scope
To ensure ethical research, the following activities are strictly prohibited:
- Distributed Denial of Service (DDoS) against download or OTA servers.
- Social engineering or phishing targeting project maintainers.
- Attacking upstream Tailscale mesh infrastructure.
- Flaws requiring prior physical hardware modification or JTAG access.
- Disclosing vulnerabilities publicly prior to our mutual disclosure window.
Reporting Process & PGP Contact
To submit a security advisory or report a flaw, email our engineering security desk. Please encrypt sensitive technical proofs of concept using our security PGP key:
Safe Harbor Guarantee
If you conduct vulnerability research in accordance with this policy, Cyronix Dev & Security considers your activity authorized under computer crime and anti-circumvention statutes. We will not pursue legal action against researchers acting in good faith.