← Lector

Security Policy

Last updated: October 7, 2026

Supported versions

Lector is a rolling release. Only the latest version on the main branch and the most recent published build get security fixes. If you're on an older build, update before reporting.

Reporting a vulnerability

Please don't open a public GitHub issue for a security vulnerability. Report it privately instead:

Please include:

What to expect

Please allow a reasonable window for a fix to ship before you disclose anything publicly.

Scope

Lector is an unsandboxed menu bar app, built with the hardened runtime and distributed directly rather than through the App Store. It holds the Screen Recording permission and registers global hot keys. When you press a shortcut, it captures part of the screen with macOS's screenshot tool, reads the text with Apple's Vision and a bundled Tesseract, and translates it with Apple's Translation or an offline Opus-MT model running on ONNX Runtime.

These are in scope:

Bugs in Tesseract, Leptonica, or ONNX Runtime themselves belong upstream. Tell us as well if Lector ships an affected version.

Don't put real screenshots of private content in a report. Use a test image or redact it.