Report privately through GitHub: open a draft security advisory.
Please do not open a public issue, pull request, or discussion for a suspected vulnerability.
Helpful details, when you have them:
- affected version (
mt version) and macOS version - steps to reproduce, or a proof of concept
- what an attacker gains
- acknowledgement within 7 days
- a fix or a decision on the report before the advisory is published
- credit in the advisory, unless you prefer to stay anonymous