Post

Savant
Savant@WabiSabi777_·
@rmoskovy @session_app the window.getUserKeys() (which returns Ed25519 private key) is explicitly exposed on the global window object via preload.js. This means any XSS in the renderer = immediate key exfil with zero require() calls needed. Still hunting for the XSS sink tho any ideas 🤔?
English
1
0
3
348
分享