Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
Domain Spoofing Vuln in Status Android Wallet | Better HN
Domain Spoofing Vuln in Status Android Wallet
(opens in new tab)
(github.com)
3 points
hackideiomat
2y ago
1 comments
Share
1 comments
default
newest
oldest
hackideiomat
OP
2y ago
This android wallet has an internal browser and it incorrectly strips www. from hosts. This also affects their permission system, meaning this is the perfect bug to phish users.
They didn't answer multiple mails in 30 days, so it's being disclosed.
j
/
k
navigate · click thread line to collapse