Ditto’s bug was arbitrary JavaScript in the app WebView (XSS), not RCE, from which they could drive the app. Including the session keys, but no stealing of the key.
Login to reply
Replies (1)
TY. So anything loading into the JS vm. Interesting the session keys are available to the JS window but nsec is not?