Skip to content

Security: PrivacyOnion/OnionShield-Windows

Security

SECURITY.md

Security

Project status

OnionShield 0.3.1 is an unaudited prototype. It must not be presented as a guarantee of anonymity or as an equivalent replacement for Mullvad VPN or Tor Browser. Known limitations are documented in README.md.

Reporting a vulnerability

Do not immediately publish a working exploit or personal data in a public issue. Prefer GitHub Private Vulnerability Reporting when it is enabled for this repository. Include the OnionShield version, Windows version, smallest reproducible network setup, and observed impact. Remove sensitive addresses and destinations from logs.

Priority scope

  • IPv4, IPv6, or DNS traffic escaping the TUN;
  • bypasses of strict_route;
  • Windows service, named-pipe, ProgramData, or Program Files permission problems;
  • unsafe recovery after Tor, sing-box, or service crashes;
  • Tor or sing-box configuration injection;
  • unintended service installation or network changes in diagnostic/test modes.

Blocking by a Tor exit, lack of arbitrary UDP support, and fingerprinting in a normal browser are documented limitations rather than new vulnerabilities.

There aren't any published security advisories