Please report security issues privately rather than in a public issue: use GitHub's private vulnerability reporting for this repository.
Please include the macOS version, the chip (Apple silicon or Intel), how ActiveBrowser was installed, and steps to reproduce. I'll acknowledge within a few days. This is a personal project with no paid support, so please don't expect a same-day response.
Only the latest release is supported. There are no backports.
The app is ad-hoc signed, not notarized. There is no Apple Developer ID behind it. The
curl | sh installer works without a Gatekeeper prompt because curl does not set the
com.apple.quarantine attribute — not because the bundle carries any trusted signature.
If that trade-off isn't acceptable to you, build from source instead; it takes one command.
install.sh verifies a SHA-256 checksum published alongside the release, and validates
the bundle identifier and architecture before replacing anything in /Applications. That
protects against a corrupted or truncated download. It does not protect against a
compromised GitHub account, since the checksum is published by the same workflow that
builds the artefact.
The installer writes to /Applications and never uses sudo. If /Applications is
not writable by your user, it refuses rather than escalating.
What ActiveBrowser sees, what it never does, and what it stores are described in one place: README.md → Privacy.