So this is just an RCE? So even nip46 (bunker) users would have their session keys stolen correct? I don't use amber, but I assume if users relaxed Ditto permissions the RCE would allow carte blanche signing?
Login to reply
Replies (2)
Ditto’s bug was arbitrary JavaScript in the app WebView (XSS), not RCE, from which they could drive the app. Including the session keys, but no stealing of the key.
If in theory it was tampered with you'd just have to revoke it in your signer. I don't think anyone exploited it in the wild.