XSS in Trezor Connect legacy versions #47
mroz22
announced in
Past Security Issues
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Details
We were notified by Jun Kokatsu that there were XSS vulnerabilities, similar to those reported in August 2020 (see #46). These vulnerabilities were present in the deprecated versions of Trezor Connect that were however still available to legacy implementations on urls https://trezor.connect.io/5, https://trezor.connect.io/6 and https://trezor.connect.io/7.
We are not aware of any abuse and users funds were safe. This issue posed a potential threat of a phishing attack which could gain more trust by changing content served from the trezor.io domain.
Fix
The issue was fixed by removing those affected versions completely.
Beta Was this translation helpful? Give feedback.
All reactions