Binocular parses untrusted, often deliberately hostile binaries, so parser robustness is a security surface. If you find a vulnerability in Binocular — a crash or memory-safety issue triggered by a crafted file, a sandbox or privilege problem in the app, or anything in the update or licensing flow — please report it privately.
Email support@hunterworks.software with SECURITY in the subject line.
Include what you can:
- Binocular version and Windows version
- Steps to reproduce, or a description of the flaw
- For file-triggered issues: the SHA-256 of the triggering file. If the file is not malware and you're comfortable sharing it, an attachment or link is welcome. If it is malware, never attach or link it — hash only, and we'll arrange a safe exchange if needed.
You'll get a reply from the developer directly. Please allow a few days, and please don't open a public issue for an unpatched vulnerability.
Binocular's analysis is 100% static — it never executes, decrypts or decompresses the files it opens. Reports that a file displays incorrectly are ordinary bugs and welcome in the public tracker; reports that a file can make Binocular itself misbehave belong here.