Friday, May 29, 2026
The BLOCKCHAIN Page
No Result
View All Result
  • Home
  • Cryptocurrency
  • Blockchain
  • Bitcoin
  • Market & Analysis
  • Altcoins
  • DeFi
  • Ethereum
  • Dogecoin
  • XRP
  • Regulations
  • NFTs
The BLOCKCHAIN Page
No Result
View All Result
Home Ethereum

Security Alert – Mist can be vulnerable when navigating to malicious DApps

by admin
December 2, 2023
in Ethereum
0
Dodging a bullet: Ethereum State Problems
0
SHARES
15
VIEWS
Share on FacebookShare on Twitter


Mist leaks some low stage APIs, which Dapps might use to realize entry to the pc’s file system and browse/delete recordsdata. This may solely have an effect on you in case you navigate to an untrusted Dapp that is aware of about these vulnerabilities and particularly tries to assault customers. Upgrading Mist is very advisable to stop publicity to assaults.

Affected configurations: All variations of Mist from 0.8.6 and decrease. This vulnerability does not have an effect on the Ethereum Pockets since it might’t load exterior DApps.
Chance: Medium
Severity: Excessive

Abstract

Some Mist API strategies have been uncovered, making it attainable for malicious webpages to realize entry to a privileged interface that might delete recordsdata on the native filesystem or launch registered protocol handlers and procure delicate data, such because the consumer listing or the consumer’s “coinbase”.
Susceptible uncovered mist APIs:

mist.shell

mist.dirname

mist.syncMinimongo

web3.eth.coinbase

is now

null

, if the account will not be allowed for the dapp

Resolution

Improve to the latest version of the Mist Browser. Don’t use any earlier Mist variations to navigate to any untrusted webpage, or native webpages from unknown origins. The Ethereum Pockets will not be affected because it does not enable navigation to exterior pages.
It is a good reminder that Mist is at present solely thought of for Ethereum App Improvement and shouldn’t be used for finish customers to navigate on the open internet till it has reached not less than model 1.0. An exterior audit of Mist is scheduled for December.

An enormous thanks goes to @tintinweb for his very helpful replica app to check the vulnerabilities!

We’re additionally considering of including Mist to the bounty program, in case you discover vulnerabilities or extreme bugs please contract us at bounty@ethereum.org




Source link

Tags: AlertDAppsmaliciousMistNavigatingSecurityVulnerable
admin

admin

Recommended

Momentum Reignites As Bulls Aim For $0.75

Bulls Aim For Fresh Surge To $0.70

2 years ago
Top 10 Crypto-Friendly Countries In 2024

Top 10 Crypto-Friendly Countries In 2024

2 years ago

Popular News

  • Protocol-Owned Liquidity: A Sustainable Path for DeFi

    Protocol-Owned Liquidity: A Sustainable Path for DeFi

    0 shares
    Share 0 Tweet 0
  • Cryptocurrency for College: Exploring DeFi Scholarship Models

    0 shares
    Share 0 Tweet 0
  • What are rebase tokens, and how do they work?

    0 shares
    Share 0 Tweet 0
  • What is Velodrome Finance (VELO): why it’s a next-gen AMM

    0 shares
    Share 0 Tweet 0
  • $10 XRP Price Envisioned By Fund Manager As Ripple Mounts Trillion-Dollar Payment Markets ⋆ ZyCrypto

    0 shares
    Share 0 Tweet 0

Latest

Ripple Makes New Demands From SEC, What Are They Asking For?

Ripple Makes New Demands From SEC, What Are They Asking For?

May 29, 2026
This Lenovo laptop I tested rivals the MacBook Air in ways Windows PCs once struggled in

This Lenovo laptop I tested rivals the MacBook Air in ways Windows PCs once struggled in

May 29, 2026

Categories

  • Altcoins
  • Bitcoin
  • Blockchain
  • Cryptocurrency
  • DeFi
  • Dogecoin
  • Ethereum
  • Market & Analysis
  • NFTs & Metaverse
  • Regulations
  • XRP

Follow us

Recommended

  • Ripple Makes New Demands From SEC, What Are They Asking For?
  • This Lenovo laptop I tested rivals the MacBook Air in ways Windows PCs once struggled in
  • AI Model Release Tracker: Opus 4.8’s misalignment rates similar to Claude Mythos Preview
  • Why a Bluetooth upgrade for AirPods excites me more than cameras or AI
  • Whoop vs. Fitbit Air: I’ve tested both trackers for health and fitness, and this model wins
  • About us
  • Privacy Policy
  • Terms & Conditions

© 2023 TheBlockchainPage | All Rights Reserved

No Result
View All Result
  • Home
  • Cryptocurrency
  • Blockchain
  • Bitcoin
  • Market & Analysis
  • Altcoins
  • DeFi
  • Ethereum
  • Dogecoin
  • XRP
  • Regulations
  • NFTs

© 2023 TheBlockchainPage | All Rights Reserved