Acknowledgements
We thank everyone who has reported a security vulnerability to us and given us the time to fix it. That cooperation makes our products safer.
On request, we name reporters here and in the corresponding advisory. We do so only with explicit consent, and we ask beforehand how the name should appear. Without consent, we name no one.
This page is not a bug bounty programme. What we commit to and what we do not is set out in our coordinated vulnerability disclosure policy.
No names are listed here so far.