Vulnerability Summary
HackerOne disclosed report --> https://hackerone.com/reports/3507241 by aszx87410
The Starknet Snap by Consensys contains a critical security vulnerability that allows malicious websites to bypass user authorization when signing messages or transactions. The vulnerability exists in the enableAuthorize parameter which can be controlled by any website. When set to false, the confirmation dialog is not shown to the user, allowing a malicious website to sign arbitrary messages or transactions without user approval, potentially leading to asset theft.
No comments yet.
Be the first to share your thoughts
Log in to join the discussion.
Sign In