Replies (1)

That's the concern for users that enabled auto-allow for amber specifically, the xss would have the ability sign arbitrary requests on behalf of the user. For nip46 aka bunker users, it would be a Harvest Now, Decrypt Later attack with exfiltrated session keys.