Only the latest GitHub Release and current main are considered for security fixes. Older builds may not be patched.
KytyPlus is experimental hobby software. It is not a hardened product. Treat it like other early emulators: run it on a machine you’re comfortable using for that purpose.
Please report:
- Remote code execution or unexpected native code execution from untrusted inputs (e.g. malformed files the emulator parses)
- Path traversal / arbitrary file write outside intended paths
- Credential or token leakage introduced by KytyPlus itself
- Dependency issues that clearly affect the emulator binaries we ship
- Game crashes, hangs, black screens, wrong graphics/audio (use a Bug or Compatibility issue)
- Missing HLE, incomplete GPU features, or “game doesn’t boot”
- Someone using KytyPlus with illegal dumps (legal problem, not a vuln report)
- Theoretical risks with no practical impact
Do not open a public issue with exploit details if the impact is serious.
- Email or contact the repository owner via GitHub (see the profile / repo owner) with:
- KytyPlus version or commit
- Description of the issue
- Steps to reproduce
- Impact assessment
- Give a reasonable time to respond before public disclosure (e.g. 90 days unless we agree otherwise).
If GitHub Private vulnerability reporting is enabled for this repo, you may use that instead (Settings → Code security).
- KytyPlus does not ship games or Sony firmware.
- Third-party libraries (Qt, Vulkan SDK components, etc.) have their own upstream security processes — report those upstream when appropriate, and tell us if our packaging is affected.
Responsible reports that help keep testers safer are appreciated.