@froge Dude. The application never inspects any data from untrusted sources. If using the kernel wg, it never inspects any data at all, only configures the kernel wg interface per your settings. There is zero attack surface.
Attack surface is stuff like a chat app decoding complex media formats, a browser trying to run arbitrary code in a sandbox, or at least a fucking ASN.1 parser. Not a local tool for configuring your network settings.
But in any case you're being a jerk and disrespecting the most important part: nobody consented to being tracked or outed as a wireguard user to networks we may connect to.