Skip to content

Security: OneDeadMachine-Dev/RTXDarwin

SECURITY.md

Security policy

RTXDarwin runs in the macOS kernel and talks directly to a PCIe GPU. A defect can panic macOS, corrupt memory, hang the PCIe fabric, or lose unsaved data. There is no supported production release yet.

Reporting a vulnerability

Please use GitHub's private vulnerability reporting for this repository. Do not include firmware, VBIOS images, machine serial numbers, MAC addresses, hostnames, GPU UUIDs, or secrets. A minimal sanitized log and the RTXDarwin commit SHA are sufficient for the first report.

Do not open a public issue for an exploitable kernel memory-safety bug until a fix or mitigation is available.

Supported versions

No version is currently security-supported. The main branch is a research bootstrap. Hardware execution is limited to physical-presence experiments on an isolated SATA SSD with Linux recovery available.

There aren't any published security advisories