Close Menu
Altcoin ObserverAltcoin Observer
  • Regulation
  • Bitcoin
  • Altcoins
  • Market
  • Analysis
  • DeFi
  • Security
  • Ethereum
Categories
  • Altcoins (1,401)
  • Analysis (1,587)
  • Bitcoin (2,173)
  • Blockchain (1,275)
  • DeFi (1,496)
  • Ethereum (1,487)
  • Event (56)
  • Exclusive Deep Dive (1)
  • Landscape Ads (2)
  • Market (1,540)
  • Press Releases (1)
  • Reddit (824)
  • Regulation (1,438)
  • Security (2,058)
  • Thought Leadership (2)
  • Videos (41)
Hand picked
  • Iran orders crypto exchange curfew after $100M Nobitex hack
  • Mat is available for trading!
  • Bybit Dex of Bybit officially launches on Solana
  • The CoinMarketCap Party Investigation, Survey in progress
  • Ideal-finance.com is associated with international financial giants to build a new mechanism for cross-border traffic in global assets
We are social
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Facebook X (Twitter) Instagram
  • About us
  • Disclaimer
  • Terms of service
  • Privacy policy
  • Contact us
Facebook X (Twitter) Instagram YouTube LinkedIn
Altcoin ObserverAltcoin Observer
  • Regulation
  • Bitcoin
  • Altcoins
  • Market
  • Analysis
  • DeFi
  • Security
  • Ethereum
Events
Altcoin ObserverAltcoin Observer
Home»Ethereum»Safety alert – Mist can be vulnerable during navigation to malicious DAPPs
Ethereum

Safety alert – Mist can be vulnerable during navigation to malicious DAPPs

March 18, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Eth org.jpeg
Share
Facebook Twitter LinkedIn Pinterest Email


Mist discloses some low level APIs, which the DAPPs could use to access the computer file system and read / delete files. This would only affect you if you navigate to an unreliable DAPP who knows these vulnerabilities and specifically tries to attack users. The upgrade of the mist is highly recommended to prevent exposure to attacks.

Configurations affected: All versions of Mist from 0.8.6 and lower. This vulnerability does not affect the Ethereum portfolio because it cannot load external DAPPs.
Probability: AVERAGE
Severity: High

Summary

Certain API walls have been exposed, which allows malicious web pages to access a privileged interface that could delete files on the local file system or launch recorded protocol managers and obtain sensitive information, such as the user or user “Coinbase” directory. Vulnerable exposed MIST API:

mist.shell

mist.dirname

mist.syncMinimongo

web3.eth.coinbase

is now

null

If the account is not allowed for the DAPP

Solution

Upgrade Latest version of the Mist browser. Do not use previous MIST versions to navigate to an unreliable web page or local web pages from unknown origin. The Ethereum portfolio is not affected because it does not allow navigation on external pages. This is a good reminder that the mist is currently considered only for the development of Ethereum applications and should not be used so that end users can navigate on the Open Web until it has reached at least version 1.0. An external audit of the mist is scheduled for December.

A big thank you goes to @tintinweb For its very useful reproduction application to test vulnerabilities!

We also plan to add mist on the Bounty program, if you find vulnerabilities or serious bugs, please contract us reboundy@ethereum.org




Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleThe index for fear and greed of BTC signals prudence, but should you buy at $ 82,000?
Next Article AI feeds the fourth industrial revolution

Related Posts

Ethereum

Here is why the prices Ethereum, Dogecoin and XRP have suffered a wiping

June 21, 2025
Ethereum

Ethereum Historic Rally Bresse: new top of all time at hand in 2025

June 21, 2025
Ethereum

Bloomberg analysts revise the “90% or more” ETF approval ratings as dry requests have changed the deposits

June 20, 2025
Add A Comment
Leave A Reply Cancel Reply

Single Page Post
Share
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Featured Content
Event

Philippine Blockchain Week 2025 Welcomes Global Web3 Trailblazers to Manila

June 9, 2025

Manila, Philippines – June 9, 2025 — As Philippine Blockchain Week (PBW) 2025 returns for…

Event

ETHMilan 2025 Returns With a Stellar Line-Up at One of Milan’s Most Iconic Venues

June 5, 2025

Milan, Italy – Mark your calendars! ETHMilan, Italy’s largest international Ethereum and Web3 conference, is…

1 2 3 … 49 Next
  • Facebook
  • Twitter
  • Instagram
  • YouTube

Bybit Dex of Bybit officially launches on Solana

June 21, 2025

Bitcoin is ready to reach a new record of once every time once the BTC breaks above this level of resistance, according to Trader Michaël Van de Poppe

June 21, 2025

Hacked coinmarketcap, rushes to eliminate the malicious portfolio check window

June 21, 2025
Facebook X (Twitter) Instagram LinkedIn
  • About us
  • Disclaimer
  • Terms of service
  • Privacy policy
  • Contact us
© 2025 Altcoin Observer. all rights reserved by Tech Team.

Type above and press Enter to search. Press Esc to cancel.

bitcoin
Bitcoin (BTC) $ 102,779.54
ethereum
Ethereum (ETH) $ 2,402.80
tether
Tether (USDT) $ 1.00
xrp
XRP (XRP) $ 2.09
bnb
BNB (BNB) $ 633.61
solana
Solana (SOL) $ 138.49
usd-coin
USDC (USDC) $ 1.00
tron
TRON (TRX) $ 0.274826
dogecoin
Dogecoin (DOGE) $ 0.15861
staked-ether
Lido Staked Ether (STETH) $ 2,399.13