Security advisories
Fixed vulnerabilities in Crosswalk and on this site, published once the fix is available.
Published advisories
No fixed vulnerability has been withheld from this list. Known vulnerabilities that are not yet fixed are tracked in our public compliance file while a fix is prepared, and appear here, in the form described below, once the fix is available; users of the affected versions are informed.
What an advisory contains
- The vulnerability, described so that a user can judge whether they are affected, with the CVE identifier once one is assigned.
- The affected product and versions, the version that carries the fix, and how the fix reaches users.
- The severity and the impact, and any workaround for users who cannot update at once.
- Credit to the reporter, when they want it.
How a fix reaches you
- The Crosswalk app updates itself: a new build installs in the background and the app offers "Restart to update". No user action beyond the restart, and no charge.
- Security updates are provided free of charge until at least 15 September 2031 (five years from 15 September 2026, when Crosswalk was first made available); the period is reviewed yearly and extended for as long as Crosswalk is offered. Only the latest version receives updates: the app installs each new version itself and asks for a restart.
- The licence worker and the website are updated by the manufacturer at the source; users receive the fix on their next request.
- The local AI helper is a downloaded binary; a fixed version is published on its download page with its checksum, and the advisory names the version.
Found something that is not on this list? Report it to [email protected]; the coordinated vulnerability disclosure policy says what happens next and when.