We actively support and provide security patches for the following versions of NavigatorOSM:
| Version | Supported |
|---|---|
| 1.3.x | ✅ |
| < 1.3.0 | ❌ |
If you discover a security vulnerability in NavigatorOSM, please do NOT open a public issue.
Instead, report it responsibly via one of the following methods:
- GitHub Private Vulnerability Reporting: Use the "Report a vulnerability" button in the Security tab of this repository.
- Email: Send details directly to lab@maribit.it with the subject line
[SECURITY] NavigatorOSM Vulnerability.
- A clear description of the vulnerability.
- Step-by-step instructions or proof-of-concept to reproduce the behavior.
- The affected component (iOS App, Cydia Repo, Android GPSTether companion, or server endpoints).
- The device model and iOS version tested (e.g., iPad Mini 1st Gen, iOS 9.3.5).
- We will acknowledge receipt of your vulnerability report within 48 hours.
- We will provide regular updates regarding our progress toward a fix.
- Once fixed, we will publish a patch and release notes with proper credit attribution (unless you prefer to remain anonymous).