Settings

Theme

Domain Spoofing Vuln in Status Android Wallet

github.com

3 points by hackideiomat 2 years ago · 1 comment

Reader

hackideiomatOP 2 years ago

This android wallet has an internal browser and it incorrectly strips www. from hosts. This also affects their permission system, meaning this is the perfect bug to phish users.

They didn't answer multiple mails in 30 days, so it's being disclosed.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection