top | item 39515077

Domain Spoofing Vuln in Status Android Wallet

3 points| hackideiomat | 2 years ago |github.com

1 comment

order

hackideiomat|2 years ago

This android wallet has an internal browser and it incorrectly strips www. from hosts. This also affects their permission system, meaning this is the perfect bug to phish users.

They didn't answer multiple mails in 30 days, so it's being disclosed.