Please do not disclose exploitable security issues in a public issue.
Until a private reporting address is published, open a GitHub security advisory in the repository. Include the affected platform and version, reproduction steps, impact, and any suggested mitigation.
Reports about bypasses are most useful when they identify a concrete unsafe behavior in this library. Device-risk signals are intentionally treated as observations, not as authoritative client-side verdicts.