Please do not open a public issue for a vulnerability that could expose local browser data. Report it privately through the security advisory feature in this GitHub repository.
Include the affected version, reproduction steps, expected impact, and any suggested mitigation. Do not include real credentials, cookies, access tokens, or personal data in a report.
Browser profiles can contain sensitive cookies and authenticated session state. Profile data stays on the local machine by default and is excluded from Git by .gitignore. Never commit or share the profile storage directory.