Skip to content

Security: openutx/TabQA

Security

SECURITY.md

Security Policy

Reporting a security issue

Email security reports to support@openutx.cn. Include the affected TabQA version, browser version, Android version, impact, and the shortest reproducible steps.

Do not post credentials, authorization headers, private application logs, unredacted HAR files, screenshots containing personal data, or exploit details in a public GitHub issue. Use email for sensitive evidence.

Product security boundaries

  • TabQA connects only to an Android device that the user selects in the browser's WebUSB chooser and authorizes on the device.
  • ADB credentials, requests, logs, screenshots, video, and text-recognition results are processed locally by default.
  • TabQA does not open a local network port or expose an arbitrary ADB command input.
  • Common authentication headers and fields containing token, secret, password, session, or auth are masked by default in network exports.
  • Automatic redaction cannot identify every application-specific secret. Users must review exported evidence before sharing it.

The current security and data-handling description is maintained at https://tabqa.openutx.cn/security. The privacy policy is available at https://tabqa.openutx.cn/privacy.

Supported versions

Security fixes are delivered through the current TabQA releases in the Chrome Web Store and Microsoft Edge Add-ons. The version displayed by each store is authoritative for that distribution channel.

There aren't any published security advisories