Security.

Vuoom records your screen, so the boundary matters. Here is how to report a problem.

Report a vulnerability

Please do not open a public issue. Instead use GitHub private vulnerability reporting or email anisnur19315@gmail.com with steps to reproduce. You will get an answer within a few days, and credit in the release notes unless you prefer otherwise.

Worth reporting

  • Recordings, audio or input logs leaving the machine
  • Capture or the input hook continuing after Stop
  • File read or write outside expected folders through a crafted .vuoom project
  • Any network request other than the two listed below

What the app does on the network

  1. An update check against GitHub Releases on launch. Updates are signed; the public key is pinned in the app.
  2. A one-time captions model download from Hugging Face, verified by SHA-256, only when you ask for captions.

Plus a local connection on 127.0.0.1 between the editor and the engine.

Supported versions

Only the latest release receives fixes. Vuoom updates itself, so updating is the patch.

Builds

Every installer is built by GitHub Actions from the public source. The workflow is in release.yml. Installers are not yet Authenticode-signed, which is why SmartScreen warns.