If you believe you’ve found a security vulnerability in HandBrake or our website (https://handbrake.fr) please use the "Report a vulnerability" button on the Security Tab above.
Contributors to this project are also available in #handbrake on Libera.chat IRC (irc://irc.libera.chat:6697/#handbrake). Please note, #handbrake and #handbrake-dev are public so details should only be sent to contributors via private message.
We kindly ask that you use responsible disclosure practices when alerting us to any security related issues. This allows us time to investigate and take corrective action where necessary.
Our goal is to deal with any issues reported as quickly as possible. If you do not receive a direct response from us within 24 hours, please follow up with us as we may not have received the message.
Please provide enough information for us to reproduce and validate the vulnerability.
Reports may be prepared with the assistance of automated or AI-based tools, but the reported behaviour MUST be independently verified and reproducible, and the reported vulnerability MUST pose a genuine security risk.
- HandBrake is a volunteer project and is not funded. We do not operate a bug bounty program and do not provide monetary rewards for vulnerability reports.
- Reports that are frivolous, speculative, lack sufficient information to be actionable, or otherwise fail to identify a credible security concern may be closed without further correspondence.
- When a new version of HandBrake is released, all earlier versions become end-of-life and are no longer supported.
- Releases are ad-hoc and do not follow any set release schedule.
- Any new releases will be published on our website and here on the GitHub releases page. They will also be available via in-app software updates usually within a few days of a release being published.
- Any security issues will be noted in our Release Notes, and if relevant an advisory may also be published on our GitHub Security Page.
- We do not provide responses to security questionnaires or security-scanning requests, and we do not provide security scan results.
We accept bug reports (including security reports) for the following versions:
| Version | Accepts Reports |
|---|---|
| git main (development) | ✅ |
| 1.11.x | ✅ |
| Earlier Releases | ❌ |